The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2018-5473: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A6%Feb 19, 2018
CVE-2017-5803: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A7%Feb 15, 2018
CVE-2018-6825: Use of Hard-coded Credentials9.8 CriticalN/A2%Feb 9, 2018
CVE-2017-1000475: Unquoted Search Path or Element7.8 HighN/A0%Jan 24, 2018
CVE-2018-6000: Missing Authorization9.8 CriticalN/A85%Jan 22, 2018
CVE-2016-10708: NULL Pointer Dereference7.5 HighN/A3%Jan 21, 2018
CVE-2017-18014: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jan 12, 2018
CVE-2018-0010: Improper Privilege Management6.5 MediumN/A0%Jan 10, 2018
CVE-2017-3765: Improper Authentication7.0 HighN/A0%Jan 10, 2018
CVE-2014-5394: Exposure of Sensitive Information to an Unauthorized Actor5.9 MediumN/A0%Jan 8, 2018
CVE-2017-18001: Missing Authentication for Critical Function9.8 CriticalN/A21%Dec 31, 2017
CVE-2017-17877: Undefined Security Weakness9.8 CriticalN/A1%Dec 27, 2017
CVE-2017-17831: Improper Input Validation8.8 HighN/A1%Dec 21, 2017
CVE-2017-17459: Undefined Security Weakness8.8 HighN/A2%Dec 7, 2017
CVE-2017-6679: Undefined Security Weakness6.4 MediumN/A0%Dec 1, 2017
CVE-2017-14176: Undefined Security Weakness8.8 HighN/A2%Nov 27, 2017
CVE-2017-12299: Improper Input Validation5.3 MediumN/A0%Nov 16, 2017
CVE-2017-15271: Use After Free5.9 MediumN/A19%Nov 15, 2017
CVE-2017-12084: Missing Authorization8.0 HighN/A0%Nov 7, 2017
CVE-2017-12261: Incorrect Authorization7.8 HighN/A0%Nov 2, 2017
CVE-2017-1000245: Insufficiently Protected Credentials9.8 CriticalN/A0%Nov 1, 2017
CVE-2017-10940: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A14%Oct 31, 2017
CVE-2017-16228: Undefined Security Weakness9.8 CriticalN/A0%Oct 29, 2017
CVE-2017-15906: Incorrect Permission Assignment for Critical Resource5.3 MediumN/A3%Oct 26, 2017
CVE-2017-10615: Improper Input Validation9.8 CriticalN/A2%Oct 13, 2017
1426-1450 of 1970