The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-21703: Incorrect Permission Assignment for Critical Resource6.4 MediumN/A0%Nov 27, 2024
CVE-2024-11860: Improper Authorization6.5 Medium6.9 Medium1%Nov 27, 2024
CVE-2024-53920: Improper Control of Generation of Code7.8 HighN/A1%Nov 27, 2024
CVE-2024-52951: Improper Neutralization of Input During Web Page Generation8.0 HighN/A1%Nov 27, 2024
CVE-2024-46055: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Nov 27, 2024
CVE-2024-46054: Incorrect Default Permissions9.8 CriticalN/A1%Nov 27, 2024
CVE-2024-11862: Covert Timing ChannelN/A5.1 Medium0%Nov 27, 2024
CVE-2024-53635: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Nov 27, 2024
CVE-2024-53604: Improper Control of Generation of Code9.8 CriticalN/A1%Nov 27, 2024
CVE-2024-53603: Improper Neutralization of Special Elements used in an SQL Command7.3 HighN/A1%Nov 27, 2024
CVE-2024-36464: Plaintext Storage of a Password2.7 LowN/A1%Nov 27, 2024
CVE-2024-42333: Buffer Over-read2.7 LowN/A1%Nov 27, 2024
CVE-2024-42332: Improper Encoding or Escaping of Output3.7 LowN/A1%Nov 27, 2024
CVE-2024-42331: Use After Free3.3 LowN/A0%Nov 27, 2024
CVE-2024-42330: Use of Externally-Controlled Format String9.1 CriticalN/A1%Nov 27, 2024
CVE-2024-42329: Unchecked Return Value to NULL Pointer Dereference3.3 LowN/A0%Nov 27, 2024
CVE-2024-42328: Unchecked Return Value to NULL Pointer Dereference3.3 LowN/A0%Nov 27, 2024
CVE-2024-42327: Improper Neutralization of Special Elements used in an SQL Command9.9 CriticalN/A79%Nov 27, 2024
CVE-2024-42326: Use After Free4.4 MediumN/A0%Nov 27, 2024
CVE-2024-36468: Stack-based Buffer Overflow3.0 LowN/A1%Nov 27, 2024
CVE-2024-11009: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Nov 27, 2024
CVE-2024-11025: Improper Neutralization of Special Elements used in an SQL Command5.4 MediumN/A0%Nov 27, 2024
CVE-2024-10521: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Nov 27, 2024
CVE-2024-52323: Exposure of Sensitive Information to an Unauthorized Actor8.1 HighN/A1%Nov 27, 2024
CVE-2024-11667: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A3%Nov 27, 2024
124501-124525 of 788572