The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-77194: Improper Authentication5.3 MediumN/A0%Sep 1, 2026
CVE-2026-76111: Incorrect Authorization8.8 HighN/A0%Sep 1, 2026
CVE-2026-18550: Improper Privilege Management9.8 CriticalN/A0%Sep 1, 2026
CVE-2026-11873: Generation of Error Message Containing Sensitive Information6.5 MediumN/A0%Sep 1, 2026
CVE-2026-10420: Untrusted Pointer Dereference5.5 MediumN/A0%Sep 1, 2026
CVE-2025-15613: Server-Side Request Forgery (SSRF)6.5 Medium6.9 Medium0%Sep 1, 2026
CVE-2023-54356: Inadequate Encryption Strength3.7 Low9.3 Critical0%Sep 1, 2026
CVE-2026-84165: Improper Access ControlN/A8.7 High0%Sep 1, 2026
CVE-2026-84059: Improper Neutralization of Special Elements used in a Command7.4 High2.1 Low2%Sep 1, 2026
CVE-2026-82927: Untrusted Pointer Dereference5.5 MediumN/A0%Sep 1, 2026
CVE-2026-82926: NULL Pointer Dereference5.5 MediumN/A0%Sep 1, 2026
CVE-2026-4813: Improper Control of Generation of CodeN/A9.4 Critical0%Sep 1, 2026
CVE-2026-59681: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High1%Sep 1, 2026
CVE-2026-59680: Improper Neutralization of Special Elements used in an OS Command8.0 High8.6 High2%Sep 1, 2026
CVE-2026-25706: Improper Neutralization of Special Elements used in an OS Command7.5 High7.5 High0%Sep 1, 2026
CVE-2026-19914: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 1, 2026
CVE-2026-16788: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 1, 2026
CVE-2026-16786: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 1, 2026
CVE-2026-15101: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 1, 2026
CVE-2026-78363: Improper Neutralization of Special Elements in Output Used by a Downstream Component4.8 MediumN/A0%Sep 1, 2026
CVE-2026-74916: Acceptance of Extraneous Untrusted Data With Trusted Data6.5 MediumN/A0%Sep 1, 2026
CVE-2026-13611: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Sep 1, 2026
CVE-2026-78319: Time-of-check Time-of-use (TOCTOU) Race ConditionN/A9.3 Critical0%Sep 1, 2026
CVE-2026-83772: Improper Neutralization of Special Elements used in a Command9.9 Critical8.6 High2%Sep 1, 2026
CVE-2026-77189: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Sep 1, 2026
10551-10575 of 512190