The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-12572: Cross-Site Request Forgery (CSRF)6.1 MediumN/A0%Dec 13, 2024
CVE-2024-12300: Missing Authorization3.7 LowN/A0%Dec 13, 2024
CVE-2019-25221: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Dec 13, 2024
CVE-2024-12603: Client-Side Enforcement of Server-Side Security9.8 CriticalN/A1%Dec 13, 2024
CVE-2024-9508: Out-of-bounds Read7.8 High8.5 High0%Dec 13, 2024
CVE-2024-12212: Out-of-bounds Read7.8 High8.5 High0%Dec 13, 2024
CVE-2024-12289: Improper Cleanup on Thrown Exception5.9 MediumN/A0%Dec 12, 2024
CVE-2024-55888: Improper Restriction of Rendered UI Layers or Frames7.1 HighN/A0%Dec 12, 2024
CVE-2024-55886: Improper Authentication6.9 MediumN/A0%Dec 12, 2024
CVE-2024-55885: Use of Weak Hash7.5 High6.9 Medium0%Dec 12, 2024
CVE-2024-55879: Missing Authorization9.1 CriticalN/A1%Dec 12, 2024
CVE-2024-55878: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Dec 12, 2024
CVE-2024-55877: Improper Neutralization of Directives in Statically Saved Code9.9 CriticalN/A2%Dec 12, 2024
CVE-2024-55876: Missing Authorization5.4 MediumN/A1%Dec 12, 2024
CVE-2024-55875: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A2%Dec 12, 2024
CVE-2024-55663: Improper Encoding or Escaping of Output9.8 Critical8.6 High1%Dec 12, 2024
CVE-2024-54811: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 12, 2024
CVE-2024-49071: Improper Authorization of Index Containing Sensitive Information6.5 MediumN/A1%Dec 12, 2024
CVE-2024-49147: Deserialization of Untrusted Data9.3 CriticalN/A1%Dec 12, 2024
CVE-2024-55662: Improper Neutralization of Directives in Statically Saved Code9.9 CriticalN/A1%Dec 12, 2024
CVE-2024-54810: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 12, 2024
CVE-2024-47238: Improper Input Validation7.5 HighN/A0%Dec 12, 2024
CVE-2024-31670: Buffer Copy without Checking Size of Input6.3 MediumN/A0%Dec 12, 2024
CVE-2024-55099: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Dec 12, 2024
CVE-2024-52901: Improper Validation of Specified Quantity in Input6.5 MediumN/A1%Dec 12, 2024
123026-123050 of 673429