The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2022-25478: Undefined Security Weakness7.8 HighN/A0%Jul 2, 2024
CVE-2022-25477: Insertion of Sensitive Information into Log File5.5 MediumN/A0%Jul 2, 2024
CVE-2024-39350: Authentication Bypass by Spoofing7.5 HighN/A1%Jun 28, 2024
CVE-2024-34824: Missing Authorization4.3 MediumN/A0%Jun 11, 2024
CVE-2023-51626: Stack-based Buffer Overflow8.8 HighN/A1%May 3, 2024
CVE-2023-51624: Stack-based Buffer Overflow8.8 HighN/A1%May 3, 2024
CVE-2023-29134: Improper Input Validation8.6 HighN/A1%Mar 27, 2024
CVE-2024-1178: Missing Authorization5.3 MediumN/A0%Mar 5, 2024
CVE-2023-49236: Out-of-bounds Write9.8 CriticalN/A1%Jan 9, 2024
CVE-2023-6888: Stack-based Buffer Overflow6.3 MediumN/A1%Dec 17, 2023
CVE-2023-30352: Use of Hard-coded Credentials9.8 CriticalN/A1%May 10, 2023
CVE-2021-0884: Integer Overflow or Wraparound7.8 HighN/A0%Apr 19, 2023
CVE-2022-37255: Use of Hard-coded Credentials7.5 HighN/A5%Apr 16, 2023
CVE-2022-43294: Out-of-bounds Write9.8 CriticalN/A1%Nov 14, 2022
CVE-2022-28691: Uncontrolled Resource Consumption7.5 HighN/A1%May 5, 2022
CVE-2021-26627: Improper Access Control7.5 HighN/A1%Apr 19, 2022
CVE-2021-24578: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Dec 21, 2021
CVE-2021-21940: Heap-based Buffer Overflow10.0 CriticalN/A1%Oct 12, 2021
CVE-2021-38381: Use After Free6.5 MediumN/A1%Aug 10, 2021
CVE-2021-38382: Use After Free6.5 MediumN/A1%Aug 10, 2021
CVE-2020-24918: Buffer Copy without Checking Size of Input9.8 CriticalN/A4%Apr 30, 2021
CVE-2019-20464: Improper Authentication7.5 HighN/A2%Apr 2, 2021
CVE-2021-27232: Out-of-bounds Write8.8 HighN/A2%Feb 16, 2021
CVE-2020-29000: Undefined Security Weakness7.2 HighN/A3%Jan 26, 2021
CVE-2020-24027: Out-of-bounds Write9.8 CriticalN/A2%Jan 11, 2021
76-100 of 206