The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-51554: Off-by-one Error9.1 Critical8.8 High0%Dec 5, 2024
CVE-2024-51551: Improper Validation of Specified Type of Input10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51550: Improper Validation of Specified Type of Input10.0 Critical9.3 Critical2%Dec 5, 2024
CVE-2024-51549: Absolute Path Traversal10.0 Critical9.3 Critical1%Dec 5, 2024
CVE-2024-51548: Unrestricted Upload of File with Dangerous Type9.9 Critical8.7 High1%Dec 5, 2024
CVE-2024-51546: Improper Validation of Specified Type of Input7.5 High8.7 High1%Dec 5, 2024
CVE-2024-51545: Insufficiently Protected Credentials10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-51544: External Control of System or Configuration Setting8.2 High8.8 High13%Dec 5, 2024
CVE-2024-51543: External Control of System or Configuration Setting8.2 High8.8 High0%Dec 5, 2024
CVE-2024-51542: Files or Directories Accessible to External Parties8.2 High8.8 High0%Dec 5, 2024
CVE-2024-51541: Improper Control of Filename for Include/Require Statement in PHP Program8.2 High8.8 High0%Dec 5, 2024
CVE-2024-48847: Use of Weak Hash8.2 High8.8 High0%Dec 5, 2024
CVE-2024-48846: Cross-Site Request Forgery (CSRF)7.1 High7.1 High1%Dec 5, 2024
CVE-2024-48845: Weak Password Requirements9.4 Critical9.3 Critical2%Dec 5, 2024
CVE-2024-48844: Allocation of Resources Without Limits or Throttling7.7 High7.2 High1%Dec 5, 2024
CVE-2024-48843: Allocation of Resources Without Limits or Throttling7.7 High7.6 High0%Dec 5, 2024
CVE-2024-48840: Improper Control of Generation of Code10.0 Critical9.3 Critical2%Dec 5, 2024
CVE-2024-48839: Improper Control of Generation of Code10.0 Critical9.3 Critical3%Dec 5, 2024
CVE-2024-12094: Cleartext Storage of Sensitive InformationN/A5.4 Medium0%Dec 5, 2024
CVE-2024-11317: Session Fixation10.0 Critical9.3 Critical0%Dec 5, 2024
CVE-2024-11316: Allocation of Resources Without Limits or Throttling7.5 High8.7 High1%Dec 5, 2024
CVE-2024-52270: User Interface (UI) Misrepresentation of Critical InformationN/A8.2 High0%Dec 5, 2024
CVE-2024-52564: Inclusion of Undocumented Features or Chicken Bits7.5 HighN/A1%Dec 5, 2024
CVE-2024-47133: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Dec 5, 2024
CVE-2024-45841: Incorrect Permission Assignment for Critical Resource6.5 MediumN/A0%Dec 5, 2024
123451-123475 of 612018