The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-11965: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11964: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11969: Incorrect Default Permissions8.8 HighN/A0%Nov 28, 2024
CVE-2024-11963: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium1%Nov 28, 2024
CVE-2024-11962: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium1%Nov 28, 2024
CVE-2024-11961: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium6.9 Medium1%Nov 28, 2024
CVE-2024-11960: Buffer Copy without Checking Size of Input8.8 High8.7 High2%Nov 28, 2024
CVE-2024-11959: Buffer Copy without Checking Size of Input8.8 High8.7 High2%Nov 28, 2024
CVE-2023-52922: Use After Free7.8 HighN/A0%Nov 28, 2024
CVE-2024-7747: Incorrect Conversion between Numeric Types6.5 MediumN/A0%Nov 28, 2024
CVE-2024-53731: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Nov 28, 2024
CVE-2024-8308: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A1%Nov 28, 2024
CVE-2024-53737: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Nov 28, 2024
CVE-2024-53736: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Nov 28, 2024
CVE-2024-53734: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Nov 28, 2024
CVE-2024-53733: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Nov 28, 2024
CVE-2024-53732: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Nov 28, 2024
CVE-2024-52501: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A1%Nov 28, 2024
CVE-2024-52499: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A1%Nov 28, 2024
CVE-2024-52498: Path Traversal: '.../...//'7.5 HighN/A1%Nov 28, 2024
CVE-2024-52497: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A1%Nov 28, 2024
CVE-2024-52496: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A1%Nov 28, 2024
CVE-2024-52495: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Nov 28, 2024
CVE-2024-52490: Unrestricted Upload of File with Dangerous Type10.0 CriticalN/A1%Nov 28, 2024
CVE-2024-52481: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Nov 28, 2024
124351-124375 of 788572