The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2019-5426: Improper Authentication4.8 MediumN/A1%Apr 10, 2019
CVE-2019-5425: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A2%Apr 10, 2019
CVE-2019-5424: Improper Neutralization of Special Elements used in a Command8.8 HighN/A2%Apr 10, 2019
CVE-2018-19589: Incorrect Permission Assignment for Critical Resource6.5 MediumN/A1%Apr 9, 2019
CVE-2019-0816: Use of Incorrectly-Resolved Name or Reference5.1 MediumN/A1%Apr 9, 2019
CVE-2018-10242: Out-of-bounds Read7.5 HighN/A2%Apr 4, 2019
CVE-2018-17565: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A2%Apr 1, 2019
CVE-2017-9626: Improper Access Control9.8 CriticalN/A2%Mar 27, 2019
CVE-2014-5432: DEPRECATED: Authentication Bypass Issues9.8 CriticalN/A3%Mar 26, 2019
CVE-2019-3856: Integer Overflow or Wraparound8.8 HighN/A6%Mar 25, 2019
CVE-2019-3857: Integer Overflow or Wraparound8.8 HighN/A6%Mar 25, 2019
CVE-2019-3860: Out-of-bounds Read5.0 MediumN/A5%Mar 25, 2019
CVE-2019-3861: Out-of-bounds Read9.1 CriticalN/A5%Mar 25, 2019
CVE-2019-3863: Integer Overflow or Wraparound7.5 HighN/A3%Mar 25, 2019
CVE-2019-3858: Out-of-bounds Read5.0 MediumN/A6%Mar 21, 2019
CVE-2019-3855: Integer Overflow or Wraparound8.8 HighN/A9%Mar 21, 2019
CVE-2019-3862: Improper Handling of Length Parameter Inconsistency7.3 HighN/A8%Mar 20, 2019
CVE-2019-3859: Out-of-bounds Read9.1 CriticalN/A6%Mar 20, 2019
CVE-2018-18473: Use of Hard-coded Credentials9.8 CriticalN/A6%Mar 19, 2019
CVE-2018-6517: Improper Certificate Validation7.5 HighN/A1%Mar 17, 2019
CVE-2019-3918: Use of Hard-coded Credentials9.8 CriticalN/A2%Mar 5, 2019
CVE-2018-20799: Undefined Security Weakness7.5 HighN/A2%Mar 1, 2019
CVE-2018-20798: Incorrect Permission Assignment for Critical Resource7.5 HighN/A1%Mar 1, 2019
CVE-2018-1352: Use of Externally-Controlled Format String9.8 CriticalN/A1%Feb 8, 2019
CVE-2019-7639: Incorrect Authorization8.1 HighN/A1%Feb 8, 2019
1326-1350 of 1970