The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2020-14818: Undefined Security Weakness3.0 LowN/A1%Oct 21, 2020
CVE-2020-7182: Improper Neutralization of Special Elements used in an Expression Language Statement8.8 HighN/A3%Oct 19, 2020
CVE-2020-1683: Missing Release of Memory after Effective Lifetime7.5 HighN/A1%Oct 16, 2020
CVE-2020-3404: Incorrect Authorization7.8 HighN/A0%Sep 24, 2020
CVE-2019-20916: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A3%Sep 4, 2020
CVE-2020-25092: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Sep 3, 2020
CVE-2020-25093: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Sep 3, 2020
CVE-2020-5917: Inadequate Encryption Strength5.9 MediumN/A1%Aug 26, 2020
CVE-2019-11862: Undefined Security Weakness8.1 HighN/A1%Aug 21, 2020
CVE-2020-24056: Use of Hard-coded Credentials7.5 HighN/A1%Aug 21, 2020
CVE-2020-24053: Use of Hard-coded Credentials7.5 HighN/A1%Aug 21, 2020
CVE-2020-24359: Improper Input Validation7.5 HighN/A1%Aug 20, 2020
CVE-2019-20150: Undefined Security Weakness6.5 MediumN/A1%Aug 20, 2020
CVE-2020-11733: Improper Neutralization of Special Elements used in an OS Command6.7 MediumN/A2%Aug 13, 2020
CVE-2020-16137: Undefined Security Weakness9.8 CriticalN/A19%Aug 12, 2020
CVE-2020-0247: Improper Handling of Exceptional Conditions5.5 MediumN/A0%Aug 11, 2020
CVE-2020-16134: Undefined Security Weakness8.0 HighN/A1%Aug 4, 2020
CVE-2020-16135: NULL Pointer Dereference5.9 MediumN/A4%Jul 29, 2020
CVE-2020-5763: Active Debug Code8.8 HighN/A3%Jul 29, 2020
CVE-2019-20030: Undefined Security Weakness7.8 HighN/A0%Jul 29, 2020
CVE-2020-15778: Improper Neutralization of Special Elements used in an OS Command7.4 HighN/A13%Jul 24, 2020
CVE-2020-3442: Cleartext Transmission of Sensitive Information4.8 MediumN/A0%Jul 20, 2020
CVE-2020-5759: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A3%Jul 17, 2020
CVE-2020-14580: Undefined Security Weakness8.2 HighN/A1%Jul 15, 2020
CVE-2020-15584: Improper Input Validation5.5 MediumN/A0%Jul 7, 2020
1176-1200 of 1969