The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2020-24216: Undefined Security Weakness7.5 HighN/A2%Oct 6, 2020
CVE-2020-24214: Undefined Security Weakness9.8 CriticalN/A35%Oct 6, 2020
CVE-2020-25748: Cleartext Transmission of Sensitive Information8.1 HighN/A1%Sep 25, 2020
CVE-2020-25747: Missing Authentication for Critical Function9.4 CriticalN/A2%Sep 25, 2020
CVE-2020-0387: Missing Authorization7.8 HighN/A0%Sep 17, 2020
CVE-2020-14033: Buffer Copy without Checking Size of Input9.8 CriticalN/A2%Jun 15, 2020
CVE-2020-13892: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A1%Jun 9, 2020
CVE-2020-12763: Out-of-bounds Write9.8 CriticalN/A3%May 13, 2020
CVE-2020-9349: Missing Authentication for Critical Function7.5 HighN/A1%Apr 2, 2020
CVE-2020-6095: Unchecked Return Value to NULL Pointer Dereference7.5 HighN/A3%Mar 27, 2020
CVE-2013-2569: Improper Authentication7.5 HighN/A31%Jan 29, 2020
CVE-2013-1603: Use of Hard-coded Credentials5.3 MediumN/A16%Jan 28, 2020
CVE-2013-1602: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A15%Jan 28, 2020
CVE-2013-1596: Improper Authentication5.3 MediumN/A10%Jan 24, 2020
CVE-2013-1595: Buffer Copy without Checking Size of Input9.8 CriticalN/A42%Jan 24, 2020
CVE-2017-8410: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A6%Jul 2, 2019
CVE-2017-8405: Improper Authentication7.5 HighN/A3%Jul 2, 2019
CVE-2019-5284: Undefined Security Weakness6.5 MediumN/A1%Jun 4, 2019
CVE-2019-12727: Out-of-bounds Read7.5 HighN/A1%Jun 4, 2019
CVE-2019-11560: Out-of-bounds Write9.8 CriticalN/A2%May 7, 2019
CVE-2019-9928: Out-of-bounds Write8.8 HighN/A6%Apr 24, 2019
CVE-2019-10711: Undefined Security Weakness7.5 HighN/A1%Apr 23, 2019
CVE-2019-7314: Use After Free9.8 CriticalN/A3%Feb 4, 2019
CVE-2019-6256: Improper Handling of Exceptional Conditions9.8 CriticalN/A2%Jan 14, 2019
CVE-2018-19076: Improper Authentication9.8 CriticalN/A2%Nov 7, 2018
101-125 of 206