The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-47546: Integer Underflow (Wrap or Wraparound)7.5 High6.9 Medium1%Dec 12, 2024
CVE-2024-47545: Integer Underflow (Wrap or Wraparound)7.5 High6.9 Medium1%Dec 12, 2024
CVE-2024-47544: NULL Pointer Dereference7.5 High6.8 Medium1%Dec 12, 2024
CVE-2024-47543: Out-of-bounds Read7.5 High5.1 Medium1%Dec 12, 2024
CVE-2024-47542: NULL Pointer Dereference7.5 High6.8 Medium1%Dec 12, 2024
CVE-2024-47541: Out-of-bounds Write7.5 High6.9 Medium1%Dec 12, 2024
CVE-2024-47540: Use of Uninitialized Variable9.8 Critical8.6 High1%Dec 12, 2024
CVE-2024-47539: Out-of-bounds Write9.8 Critical8.6 High1%Dec 12, 2024
CVE-2024-47538: Stack-based Buffer Overflow9.8 Critical8.6 High1%Dec 12, 2024
CVE-2024-47537: Out-of-bounds Write9.8 Critical8.6 High1%Dec 12, 2024
CVE-2024-45404: Improper Authentication8.1 HighN/A1%Dec 12, 2024
CVE-2024-45337: Undefined Security Weakness9.1 CriticalN/A3%Dec 12, 2024
CVE-2024-42448: Improper Control of Generation of Code9.9 CriticalN/A20%Dec 12, 2024
CVE-2024-37401: Out-of-bounds Read7.5 HighN/A2%Dec 12, 2024
CVE-2024-37377: Out-of-bounds Write7.5 HighN/A2%Dec 12, 2024
CVE-2024-12489: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 12, 2024
CVE-2024-12488: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 12, 2024
CVE-2024-12487: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 12, 2024
CVE-2024-12486: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 12, 2024
CVE-2024-12485: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 12, 2024
CVE-2024-12484: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Dec 12, 2024
CVE-2024-12483: Authorization Bypass Through User-Controlled Key3.7 Low6.3 Medium4%Dec 12, 2024
CVE-2024-12482: Path Traversal: '../filedir'4.3 Medium5.3 Medium1%Dec 12, 2024
CVE-2024-12481: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 12, 2024
CVE-2024-12480: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Dec 12, 2024
123201-123225 of 545471