The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-83614: Uncontrolled Resource ConsumptionN/A8.7 High0%Sep 1, 2026
CVE-2026-83613: Inefficient Algorithmic ComplexityN/A8.7 High0%Sep 1, 2026
CVE-2026-83612: Improper Handling of Case SensitivityN/A8.7 High0%Sep 1, 2026
CVE-2026-83611: Improper Validation of Syntactic Correctness of InputN/A6.9 Medium0%Sep 1, 2026
CVE-2026-83610: Improper Encoding or Escaping of OutputN/A6.3 Medium0%Sep 1, 2026
CVE-2026-83609: XML Injection (aka Blind XPath Injection)N/A8.7 High0%Sep 1, 2026
CVE-2026-83608: XML Injection (aka Blind XPath Injection)N/A8.7 High0%Sep 1, 2026
CVE-2026-83607: XML Injection (aka Blind XPath Injection)N/A8.7 High0%Sep 1, 2026
CVE-2026-83606: Uncontrolled Resource ConsumptionN/A8.7 High0%Sep 1, 2026
CVE-2026-83605: XML Injection (aka Blind XPath Injection)N/A8.7 High0%Sep 1, 2026
CVE-2026-83557: Deserialization of Untrusted Data5.6 MediumN/A1%Sep 1, 2026
CVE-2026-79686: Protection Mechanism Failure8.8 HighN/A0%Sep 1, 2026
CVE-2026-79685: Improper Neutralization of Argument Delimiters in a Command6.5 MediumN/A0%Sep 1, 2026
CVE-2026-78012: Stack-based Buffer Overflow9.8 Critical9.3 Critical0%Sep 1, 2026
CVE-2026-75538: Integer Overflow or WraparoundN/A8.2 High0%Sep 1, 2026
CVE-2026-74994: Incorrect AuthorizationN/A6.0 Medium0%Sep 1, 2026
CVE-2026-74835: Allocation of Resources Without Limits or ThrottlingN/A8.7 High0%Sep 1, 2026
CVE-2026-73812: Inconsistent Interpretation of HTTP RequestsN/A8.3 High0%Sep 1, 2026
CVE-2026-73276: Inconsistent Interpretation of HTTP RequestsN/A8.3 High0%Sep 1, 2026
CVE-2026-73270: Improper Handling of Case SensitivityN/A8.2 High1%Sep 1, 2026
CVE-2026-71562: Improper Validation of Specified Quantity in InputN/A6.3 Medium0%Sep 1, 2026
CVE-2026-71380: Missing Release of Resource after Effective LifetimeN/A8.7 High0%Sep 1, 2026
CVE-2026-70409: Improper Validation of Specified Quantity in InputN/A6.3 Medium0%Sep 1, 2026
CVE-2026-70405: Improper Validation of Specified Quantity in InputN/A6.3 Medium0%Sep 1, 2026
CVE-2026-70399: Allocation of Resources Without Limits or ThrottlingN/A8.7 High1%Sep 1, 2026
10426-10450 of 612018