The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-73741: Improper Access Control4.3 MediumN/A0%Sep 1, 2026
CVE-2026-73740: Improper Privilege Management4.4 MediumN/A0%Sep 1, 2026
CVE-2026-73739: Exposure of Sensitive Information to an Unauthorized Actor4.4 MediumN/A0%Sep 1, 2026
CVE-2026-73738: Exposure of Sensitive Information to an Unauthorized Actor4.7 MediumN/A0%Sep 1, 2026
CVE-2026-73737: Improper Limitation of a Pathname to a Restricted Directory4.8 MediumN/A0%Sep 1, 2026
CVE-2026-73736: Files or Directories Accessible to External Parties5.3 MediumN/A0%Sep 1, 2026
CVE-2026-73735: Files or Directories Accessible to External Parties5.4 MediumN/A0%Sep 1, 2026
CVE-2026-73734: URL Redirection to Untrusted Site5.4 MediumN/A0%Sep 1, 2026
CVE-2026-73733: Improper Authentication5.4 MediumN/A0%Sep 1, 2026
CVE-2026-73732: Exposure of Sensitive Information to an Unauthorized Actor5.6 MediumN/A0%Sep 1, 2026
CVE-2026-73731: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 1, 2026
CVE-2026-73730: Improper Privilege Management6.5 MediumN/A0%Sep 1, 2026
CVE-2026-73729: Improper Privilege Management6.5 MediumN/A0%Sep 1, 2026
CVE-2026-73728: Uncontrolled Resource Consumption6.5 MediumN/A0%Sep 1, 2026
CVE-2026-73727: Incorrect Authorization6.5 MediumN/A0%Sep 1, 2026
CVE-2026-73726: Missing Authentication for Critical Function6.8 MediumN/A0%Sep 1, 2026
CVE-2026-73725: Improper Privilege Management7.0 HighN/A0%Sep 1, 2026
CVE-2026-73724: Incorrect Authorization7.1 HighN/A0%Sep 1, 2026
CVE-2026-73723: Incorrect Authorization7.1 HighN/A0%Sep 1, 2026
CVE-2026-73722: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Sep 1, 2026
CVE-2026-73721: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Sep 1, 2026
CVE-2026-73720: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Sep 1, 2026
CVE-2026-73719: External Control of File Name or Path7.2 HighN/A0%Sep 1, 2026
CVE-2026-73718: Cross-Site Request Forgery (CSRF)7.4 HighN/A0%Sep 1, 2026
CVE-2026-73717: Improper Neutralization of Special Elements used in an OS Command7.5 HighN/A1%Sep 1, 2026
10276-10300 of 612018