The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-73564: Improper Validation of Array IndexN/A8.7 High0%Aug 13, 2026
CVE-2026-67614: Use of Hard-coded Credentials9.8 Critical9.3 Critical1%Aug 13, 2026
CVE-2026-67613: Improper Limitation of a Pathname to a Restricted Directory4.9 Medium6.9 Medium0%Aug 13, 2026
CVE-2026-56657: Improper Access Control6.2 MediumN/A0%Aug 13, 2026
CVE-2026-73430: Improper Check for Unusual or Exceptional Conditions5.3 MediumN/A0%Aug 12, 2026
CVE-2026-73429: Incorrect Type Conversion or Cast5.3 MediumN/A0%Aug 12, 2026
CVE-2026-5917: Improper Neutralization of Special Elements used in an OS Command8.8 High8.6 High1%Aug 11, 2026
CVE-2026-73283: Always-Incorrect Control Flow Implementation2.5 LowN/A0%Aug 11, 2026
CVE-2026-73282: Use After Free4.8 MediumN/A0%Aug 11, 2026
CVE-2026-73281: Incorrect Resource Transfer Between Spheres3.5 LowN/A0%Aug 11, 2026
CVE-2026-73227: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A0%Aug 11, 2026
CVE-2026-73226: Improper Control of Dynamically-Managed Code Resources8.8 HighN/A0%Aug 11, 2026
CVE-2026-73225: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A0%Aug 11, 2026
CVE-2026-73224: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A0%Aug 11, 2026
CVE-2026-73223: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A0%Aug 11, 2026
CVE-2026-72913: Improper Neutralization of Special Elements used in a CommandN/A7.3 High0%Aug 10, 2026
CVE-2026-72903: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A0%Aug 10, 2026
CVE-2026-72902: Improper Neutralization of Special Elements used in an OS Command9.9 CriticalN/A1%Aug 10, 2026
CVE-2026-72882: Improper Neutralization of Special Elements used in an OS Command9.9 CriticalN/A0%Aug 10, 2026
CVE-2026-72877: Improper Neutralization of Special Elements used in an OS Command9.6 CriticalN/A0%Aug 10, 2026
CVE-2026-72876: Improper Neutralization of Special Elements used in an OS Command9.9 CriticalN/A1%Aug 10, 2026
CVE-2026-71965: Insufficient Verification of Data Authenticity8.8 High8.7 High0%Aug 10, 2026
CVE-2025-13293: Use of Hard-coded CredentialsN/A9.3 Critical0%Aug 10, 2026
CVE-2026-72740: Improper Neutralization of Special Elements used in an OS Command9.9 CriticalN/A1%Aug 10, 2026
CVE-2026-72736: Improper Neutralization of Special Elements used in a Command9.9 CriticalN/A0%Aug 10, 2026
101-125 of 1969