The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2023-38408: Unquoted Search Path or Element9.8 CriticalN/A80%Jul 20, 2023
CVE-2023-37268: Improper Authentication6.4 MediumN/A1%Jul 14, 2023
CVE-2023-37462: Improper Neutralization of Special Elements in Output Used by a Downstream Component9.9 CriticalN/A92%Jul 14, 2023
CVE-2023-38325: Improper Certificate Validation7.5 HighN/A1%Jul 14, 2023
CVE-2023-37948: Improper Input Validation3.7 LowN/A0%Jul 12, 2023
CVE-2020-20021: Uncontrolled Resource Consumption7.5 HighN/A1%Jul 12, 2023
CVE-2023-29131: Incorrect Default Permissions7.4 HighN/A0%Jul 11, 2023
CVE-2023-35887: Improper Limitation of a Pathname to a Restricted Directory5.0 MediumN/A1%Jul 10, 2023
CVE-2023-36611: Improper Authorization6.5 MediumN/A1%Jul 3, 2023
CVE-2023-37237: Incorrect Permission Assignment for Critical Resource6.5 MediumN/A1%Jun 29, 2023
CVE-2022-44719: Incorrect Permission Assignment for Critical Resource7.5 HighN/A1%Jun 29, 2023
CVE-2023-34254: Improper Neutralization of Special Elements used in an OS Command7.6 HighN/A1%Jun 23, 2023
CVE-2023-25435: Buffer Copy without Checking Size of Input5.5 MediumN/A0%Jun 21, 2023
CVE-2023-25187: Use of Hard-coded Credentials6.3 MediumN/A1%Jun 16, 2023
CVE-2023-28175: Exposure of Sensitive Information to an Unauthorized Actor7.1 HighN/A0%Jun 15, 2023
CVE-2023-33964: Improper Input Validation8.6 HighN/A1%May 31, 2023
CVE-2022-45853: Improper Privilege Management6.7 MediumN/A0%May 30, 2023
CVE-2022-24630: Improper Neutralization of Special Elements used in a Command7.2 HighN/A24%May 29, 2023
CVE-2023-2283: Improper Authentication6.5 MediumN/A1%May 26, 2023
CVE-2023-1667: NULL Pointer Dereference6.5 MediumN/A1%May 26, 2023
CVE-2023-28319: Use After Free7.5 HighN/A2%May 26, 2023
CVE-2023-1944: Use of Hard-coded Password8.4 HighN/A0%May 24, 2023
CVE-2023-2588: Inclusion of Web Functionality from an Untrusted Source8.8 HighN/A1%May 22, 2023
CVE-2023-33235: Improper Neutralization of Special Elements used in a Command7.2 HighN/A1%May 22, 2023
CVE-2023-32069: Incorrect Authorization9.9 CriticalN/A1%May 9, 2023
876-900 of 1969