The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-10704: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Nov 29, 2024
CVE-2024-48651: Incorrect Authorization7.5 HighN/A2%Nov 29, 2024
CVE-2024-45495: Origin Validation Error4.3 MediumN/A0%Nov 29, 2024
CVE-2024-35451: Server-Side Request Forgery (SSRF)4.8 MediumN/A0%Nov 29, 2024
CVE-2024-54124: Incorrect Authorization8.8 HighN/A0%Nov 29, 2024
CVE-2024-54123: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 29, 2024
CVE-2024-11979: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Nov 29, 2024
CVE-2024-11978: Absolute Path Traversal7.5 HighN/A1%Nov 29, 2024
CVE-2024-9852: Uncontrolled Search Path Element7.8 HighN/A0%Nov 28, 2024
CVE-2024-8300: Dead Code7.0 HighN/A0%Nov 28, 2024
CVE-2024-8299: Uncontrolled Search Path Element7.8 HighN/A0%Nov 28, 2024
CVE-2024-11971: Improper Neutralization of Input During Web Page Generation3.5 Low5.3 Medium1%Nov 28, 2024
CVE-2024-11970: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11968: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Nov 28, 2024
CVE-2024-11967: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11966: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-52338: Deserialization of Untrusted Data9.8 CriticalN/A2%Nov 28, 2024
CVE-2024-11965: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11964: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11969: Incorrect Default Permissions8.8 HighN/A0%Nov 28, 2024
CVE-2024-11963: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Nov 28, 2024
CVE-2024-11962: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11961: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium6.9 Medium1%Nov 28, 2024
CVE-2024-11960: Buffer Copy without Checking Size of Input8.8 High8.7 High2%Nov 28, 2024
CVE-2024-11959: Buffer Copy without Checking Size of Input8.8 High8.7 High2%Nov 28, 2024
124326-124350 of 788572