The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-51760: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-51757: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-51756: Improper Access Control5.9 MediumN/A0%Sep 1, 2026
CVE-2026-51754: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-51752: Improper Access Control5.3 MediumN/A0%Sep 1, 2026
CVE-2026-51751: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-51750: Improper Access Control9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-51748: Improper Access Control5.9 MediumN/A0%Sep 1, 2026
CVE-2026-19513: Unrestricted Upload of File with Dangerous Type8.1 HighN/A1%Sep 1, 2026
CVE-2026-18808: Improper Control of Generation of Code9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-18210: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-16675: Improper Restriction of Excessive Authentication AttemptsN/A8.5 High0%Sep 1, 2026
CVE-2026-13348: Improper Restriction of Excessive Authentication AttemptsN/A6.9 Medium0%Sep 1, 2026
CVE-2026-13337: SQL Injection: HibernateN/A5.1 Medium0%Sep 1, 2026
CVE-2026-13336: Improper Neutralization of Special Elements used in an OS CommandN/A7.3 High1%Sep 1, 2026
CVE-2026-12663: Missing Authentication for Critical FunctionN/A7.0 High0%Sep 1, 2026
CVE-2026-12661: Stack-based Buffer OverflowN/A4.8 Medium0%Sep 1, 2026
CVE-2025-12768: Out-of-bounds WriteN/A8.6 High0%Sep 1, 2026
CVE-2024-14047: Improper Link Resolution Before File Access7.1 HighN/A0%Sep 1, 2026
CVE-2024-10085: Allocation of Resources Without Limits or ThrottlingN/A8.2 High0%Sep 1, 2026
CVE-2026-84235: Uncontrolled Resource ConsumptionN/A8.7 High0%Sep 1, 2026
CVE-2026-84149: Exposure of Version-Control Repository to an Unauthorized Control SphereN/A9.2 Critical0%Sep 1, 2026
CVE-2026-84148: Authorization Bypass Through User-Controlled KeyN/A9.2 Critical0%Sep 1, 2026
CVE-2026-84147: Unrestricted Upload of File with Dangerous TypeN/A10.0 Critical1%Sep 1, 2026
CVE-2026-84145: Improper Restriction of Operations within the Bounds of a Memory Buffer7.5 HighN/A0%Sep 1, 2026
10476-10500 of 612018