The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-53859: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A1%Nov 27, 2024
CVE-2024-53858: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Nov 27, 2024
CVE-2024-53260: Improper Neutralization of Formula Elements in a CSV File6.8 MediumN/A0%Nov 27, 2024
CVE-2018-9350: Out-of-bounds Read6.5 MediumN/A0%Nov 27, 2024
CVE-2018-9349: Out-of-bounds Read6.5 MediumN/A0%Nov 27, 2024
CVE-2017-13323: Integer Overflow or Wraparound7.8 HighN/A0%Nov 27, 2024
CVE-2017-13321: Out-of-bounds Read5.5 MediumN/A0%Nov 27, 2024
CVE-2017-13320: Out-of-bounds Read6.5 MediumN/A0%Nov 27, 2024
CVE-2017-13319: Buffer Copy without Checking Size of Input7.5 HighN/A0%Nov 27, 2024
CVE-2017-13316: Missing Authorization7.8 HighN/A0%Nov 27, 2024
CVE-2024-53855: Improper Isolation or Compartmentalization1.9 LowN/A0%Nov 27, 2024
CVE-2024-53264: URL Redirection to Untrusted SiteN/A5.1 Medium1%Nov 27, 2024
CVE-2024-47181: Incorrect Type Conversion or Cast7.5 HighN/A1%Nov 27, 2024
CVE-2024-41126: Out-of-bounds Read8.3 HighN/A0%Nov 27, 2024
CVE-2024-41125: Out-of-bounds Read8.3 HighN/A0%Nov 27, 2024
CVE-2023-29001: Uncontrolled Recursion7.5 High8.7 High1%Nov 27, 2024
CVE-2024-9369: Improper Validation of Specified Quantity in Input9.6 CriticalN/A1%Nov 27, 2024
CVE-2024-7025: External Control of Assumed-Immutable Web Parameter8.8 HighN/A1%Nov 27, 2024
CVE-2024-53254: Undefined Security WeaknessN/AN/AN/ANov 27, 2024
CVE-2024-11160: Undefined Security WeaknessN/AN/AN/ANov 27, 2024
CVE-2024-54004: Improper Limitation of a Pathname to a Restricted Directory4.3 MediumN/A1%Nov 27, 2024
CVE-2024-54003: Improper Neutralization of Input During Web Page Generation8.0 HighN/A80%Nov 27, 2024
CVE-2024-51228: Improper Neutralization of Special Elements used in an OS Command6.8 MediumN/A4%Nov 27, 2024
CVE-2024-37816: Buffer Copy without Checking Size of Input4.2 MediumN/A0%Nov 27, 2024
CVE-2024-31976: Improper Neutralization of Special Elements used in an OS Command8.0 HighN/A1%Nov 27, 2024
124451-124475 of 788572