The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-61759: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61758: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61757: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61756: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61755: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61754: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61753: Improper Limitation of a Pathname to a Restricted Directory7.8 HighN/A0%Sep 1, 2026
CVE-2026-61752: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61751: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-61750: Deserialization of Untrusted Data7.8 HighN/A0%Sep 1, 2026
CVE-2026-58567: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 1, 2026
CVE-2026-51770: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-51769: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-51768: Improper Access Control7.5 HighN/A0%Sep 1, 2026
CVE-2026-51767: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-49329: Inefficient Algorithmic Complexity7.5 HighN/A0%Sep 1, 2026
CVE-2026-18931: Use of Hard-coded Credentials9.1 CriticalN/A0%Sep 1, 2026
CVE-2026-10195: Improper Neutralization of Special Elements used in a Command8.8 HighN/A1%Sep 1, 2026
CVE-2026-84233: Improper Neutralization of Special Elements used in an OS Command7.0 HighN/A0%Sep 1, 2026
CVE-2026-84115: Improper Privilege Management8.3 High5.5 Medium0%Sep 1, 2026
CVE-2026-84114: Improper Authentication6.3 Medium2.1 Low0%Sep 1, 2026
CVE-2026-84111: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 1, 2026
CVE-2026-84110: Client-Side Enforcement of Server-Side Security5.3 Medium5.5 Medium0%Sep 1, 2026
CVE-2026-83619: Uncontrolled Resource ConsumptionN/A8.7 High0%Sep 1, 2026
CVE-2026-83618: XML Injection (aka Blind XPath Injection)N/A8.7 High0%Sep 1, 2026
10401-10425 of 612018