The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-11012: Improper Control of Generation of Code6.3 MediumN/A0%Dec 13, 2024
CVE-2024-10783: Missing Authorization8.1 HighN/A2%Dec 13, 2024
CVE-2024-12465: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 13, 2024
CVE-2024-12421: Improper Control of Generation of Code6.5 MediumN/A0%Dec 13, 2024
CVE-2024-12420: Improper Control of Generation of Code6.5 MediumN/A0%Dec 13, 2024
CVE-2024-12417: Improper Control of Generation of Code6.5 MediumN/A0%Dec 13, 2024
CVE-2024-12414: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 13, 2024
CVE-2024-12309: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Dec 13, 2024
CVE-2024-12042: Unrestricted Upload of File with Dangerous Type5.4 MediumN/A0%Dec 13, 2024
CVE-2024-11911: Missing Authorization4.3 MediumN/A0%Dec 13, 2024
CVE-2024-11910: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 13, 2024
CVE-2024-11832: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 13, 2024
CVE-2024-11754: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 13, 2024
CVE-2024-11275: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 13, 2024
CVE-2024-55918: Improper Control of Generation of Code5.3 MediumN/A1%Dec 13, 2024
CVE-2024-12581: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%Dec 13, 2024
CVE-2024-11839: Deserialization of Untrusted Data7.5 High8.6 High0%Dec 13, 2024
CVE-2024-11838: External Control of File Name or Path9.8 Critical8.6 High0%Dec 13, 2024
CVE-2024-11837: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical8.6 High0%Dec 13, 2024
CVE-2024-11836: Server-Side Request Forgery (SSRF)7.5 High8.6 High0%Dec 13, 2024
CVE-2024-11835: Uncontrolled Resource Consumption7.5 High7.0 High0%Dec 13, 2024
CVE-2024-11834: Improper Limitation of a Pathname to a Restricted Directory9.1 Critical8.9 High1%Dec 13, 2024
CVE-2024-11833: Improper Limitation of a Pathname to a Restricted Directory9.1 Critical8.9 High1%Dec 13, 2024
CVE-2024-10939: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Dec 13, 2024
CVE-2024-10678: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 13, 2024
123001-123025 of 673429