The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-72633: Incorrect Authorization4.3 MediumN/A0%Sep 1, 2026
CVE-2026-72628: Improper Handling of Highly Compressed Data (Data Amplification)6.5 MediumN/A0%Sep 1, 2026
CVE-2026-63138: Improper Neutralization of Special Elements in Data Query Logic6.5 MediumN/A0%Sep 1, 2026
CVE-2026-63137: Incorrect Authorization8.3 HighN/A0%Sep 1, 2026
CVE-2026-56143: Allocation of Resources Without Limits or Throttling4.9 MediumN/A0%Sep 1, 2026
CVE-2026-45221: Uncontrolled Search Path Element7.8 High8.5 High0%Sep 1, 2026
CVE-2026-33465: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Sep 1, 2026
CVE-2026-19766: Improper Authentication9.6 CriticalN/A0%Sep 1, 2026
CVE-2026-8712: Server-Side Request Forgery (SSRF)8.3 High6.9 Medium0%Sep 1, 2026
CVE-2026-84306: Authentication Bypass by Capture-replay6.5 MediumN/A0%Sep 1, 2026
CVE-2026-84305: Inefficient Algorithmic ComplexityN/A5.1 Medium0%Sep 1, 2026
CVE-2026-84304: Uncontrolled Resource ConsumptionN/A8.7 High0%Sep 1, 2026
CVE-2026-84303: Improper Handling of Case SensitivityN/A6.3 Medium0%Sep 1, 2026
CVE-2026-83551: Cleartext Storage of Sensitive Information7.2 High8.5 High0%Sep 1, 2026
CVE-2026-81846: Authorization Bypass Through User-Controlled Key3.5 LowN/A0%Sep 1, 2026
CVE-2026-52295: Out-of-bounds Read2.9 LowN/A0%Sep 1, 2026
CVE-2026-52132: Uncontrolled Recursion7.5 HighN/A0%Sep 1, 2026
CVE-2026-52131: Reachable Assertion7.5 HighN/A0%Sep 1, 2026
CVE-2026-52130: Uncontrolled Recursion7.5 HighN/A0%Sep 1, 2026
CVE-2026-52111: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-52023: Uncontrolled Resource Consumption7.5 HighN/A0%Sep 1, 2026
CVE-2026-52022: Uncontrolled Resource Consumption7.5 HighN/A0%Sep 1, 2026
CVE-2026-51974: Improper Control of Generation of Code8.8 HighN/A0%Sep 1, 2026
CVE-2026-19593: External Control of System or Configuration Setting9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-19592: External Control of System or Configuration Setting7.3 HighN/A0%Sep 1, 2026
10326-10350 of 612018