The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
TitleEitWModules
CVE-2019-25694: Improper Neutralization of Special Elements used in an SQL Command9.1 Critical8.8 High0%Apr 5, 2026
CVE-2019-25692: Improper Neutralization of Special Elements used in an SQL Command9.1 Critical8.8 High0%Apr 5, 2026
CVE-2019-25690: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Apr 5, 2026
CVE-2019-25688: Improper Neutralization of Special Elements used in an SQL Command9.1 Critical8.8 High0%Apr 5, 2026
CVE-2019-25687: Improper Limitation of a Pathname to a Restricted Directory9.8 Critical9.3 Critical0%Apr 5, 2026
CVE-2019-25686: Missing Authentication for Critical Function7.5 High8.7 High0%Apr 5, 2026
CVE-2019-25685: Undefined Security WeaknessN/A8.7 High0%Apr 5, 2026
CVE-2019-25684: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Apr 5, 2026
CVE-2019-25683: Insertion of Sensitive Information into Log File5.5 Medium6.9 Medium0%Apr 5, 2026
CVE-2019-25682: Cross-Site Request Forgery (CSRF)4.3 Medium5.3 Medium0%Apr 5, 2026
CVE-2019-25681: Out-of-bounds Write7.8 High8.6 High0%Apr 5, 2026
CVE-2019-25680: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical8.8 High0%Apr 5, 2026
CVE-2019-25679: Out-of-bounds Write7.8 High8.5 High0%Apr 5, 2026
CVE-2019-25678: Missing Authentication for Critical Function7.5 High8.8 High0%Apr 5, 2026
CVE-2019-25677: Creation of Temporary File in Directory with Insecure Permissions5.5 Medium6.9 Medium0%Apr 5, 2026
CVE-2019-25676: Improper Neutralization of Input During Web Page Generation9.8 Critical8.8 High0%Apr 5, 2026
CVE-2019-25675: Improper Neutralization of Special Elements used in an SQL Command7.5 High8.8 High0%Apr 5, 2026
CVE-2019-25674: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical8.8 High0%Apr 5, 2026
CVE-2019-25672: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Apr 5, 2026
CVE-2019-25671: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High0%Apr 5, 2026
CVE-2019-25670: Out-of-bounds Write7.8 High8.6 High0%Apr 5, 2026
CVE-2019-25669: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Apr 5, 2026
CVE-2019-25668: Improper Neutralization of Special Elements used in an SQL Command8.2 High8.8 High0%Apr 5, 2026
CVE-2019-25667: Out-of-bounds Write5.5 Medium6.9 Medium0%Apr 5, 2026
CVE-2019-25666: Out-of-bounds Write5.5 Medium6.9 Medium0%Apr 5, 2026
76-100 of 17623