The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2020-1614: Use of Hard-coded Credentials10.0 CriticalN/A1%Apr 8, 2020
CVE-2020-10263: Missing Authentication for Critical Function6.8 MediumN/A1%Apr 8, 2020
CVE-2020-10262: Undefined Security Weakness6.8 MediumN/A1%Apr 8, 2020
CVE-2020-11543: Use of Hard-coded Credentials9.8 CriticalN/A3%Apr 7, 2020
CVE-2020-9473: Missing Authentication for Critical Function6.6 MediumN/A1%Apr 6, 2020
CVE-2020-3917: Undefined Security Weakness5.5 MediumN/A0%Apr 1, 2020
CVE-2020-10887: Protection Mechanism Failure9.8 CriticalN/A4%Mar 25, 2020
CVE-2020-10888: Improper Authentication9.8 CriticalN/A2%Mar 25, 2020
CVE-2020-10364: Allocation of Resources Without Limits or Throttling7.5 HighN/A3%Mar 23, 2020
CVE-2019-19148: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A8%Mar 20, 2020
CVE-2014-2723: Incorrect Default Permissions8.8 HighN/A2%Mar 19, 2020
CVE-2014-2721: Incorrect Default Permissions8.8 HighN/A2%Mar 19, 2020
CVE-2014-2722: Incorrect Default Permissions8.8 HighN/A2%Mar 19, 2020
CVE-2019-19940: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A5%Mar 16, 2020
CVE-2020-2148: Incorrect Authorization4.3 MediumN/A1%Mar 9, 2020
CVE-2020-2146: Improper Verification of Cryptographic Signature7.4 HighN/A1%Mar 9, 2020
CVE-2020-2147: Cross-Site Request Forgery (CSRF)4.3 MediumN/A1%Mar 9, 2020
CVE-2020-8994: Improper Authentication6.8 MediumN/A1%Mar 5, 2020
CVE-2015-3006: Insufficient Entropy6.5 MediumN/A1%Feb 28, 2020
CVE-2020-9355: Undefined Security Weakness9.8 CriticalN/A2%Feb 23, 2020
CVE-2020-9283: Improper Verification of Cryptographic Signature7.5 HighN/A21%Feb 20, 2020
CVE-2020-0757: Undefined Security Weakness7.8 HighN/A1%Feb 11, 2020
CVE-2020-6760: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A2%Feb 6, 2020
CVE-2020-5319: Improper Validation of Array Index7.5 HighN/A1%Feb 6, 2020
CVE-2020-6961: Plaintext Storage of a Password10.0 CriticalN/A2%Jan 24, 2020
1226-1250 of 1970