The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2017-16228: Undefined Security Weakness9.8 CriticalN/A4%Oct 29, 2017
CVE-2017-15906: Incorrect Permission Assignment for Critical Resource5.3 MediumN/A3%Oct 26, 2017
CVE-2017-10615: Improper Input Validation9.8 CriticalN/A2%Oct 13, 2017
CVE-2015-6358: Improper Certificate Validation5.9 MediumN/A1%Oct 12, 2017
CVE-2017-1000117: URL Redirection to Untrusted Site8.8 HighN/A78%Oct 5, 2017
CVE-2017-1000116: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A6%Oct 5, 2017
CVE-2015-7256: Undefined Security Weakness5.9 MediumN/A1%Sep 28, 2017
CVE-2017-5200: Undefined Security Weakness8.8 HighN/A3%Sep 26, 2017
CVE-2015-8251: Exposure of Sensitive Information to an Unauthorized Actor5.9 MediumN/A1%Sep 25, 2017
CVE-2017-12928: Use of Hard-coded Credentials9.8 CriticalN/A3%Sep 21, 2017
CVE-2017-6720: Improper Restriction of Operations within the Bounds of a Memory Buffer6.5 MediumN/A1%Sep 21, 2017
CVE-2017-14115: Use of Hard-coded Credentials8.1 HighN/A4%Sep 3, 2017
CVE-2015-7255: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A2%Aug 29, 2017
CVE-2014-8428: Undefined Security Weakness9.8 CriticalN/A2%Aug 28, 2017
CVE-2017-12836: Undefined Security Weakness7.5 HighN/A6%Aug 24, 2017
CVE-2017-12976: Improper Input Validation8.8 HighN/A3%Aug 20, 2017
CVE-2017-6767: Improper Privilege Management7.1 HighN/A1%Aug 17, 2017
CVE-2017-12426: Improper Input Validation8.8 HighN/A4%Aug 14, 2017
CVE-2017-9800: Improper Input Validation9.8 CriticalN/A19%Aug 11, 2017
CVE-2015-3170: Undefined Security Weakness5.5 MediumN/A0%Jul 21, 2017
CVE-2017-11361: Improper Privilege Management8.8 HighN/A1%Jul 17, 2017
CVE-2017-11353: Concurrent Execution using Shared Resource with Improper Synchronization5.9 MediumN/A1%Jul 17, 2017
CVE-2017-10601: Improper Authentication9.8 CriticalN/A2%Jul 17, 2017
CVE-2016-4996: Undefined Security Weakness7.0 HighN/A0%Jul 17, 2017
CVE-2017-2298: Improper Input Validation6.5 MediumN/A1%Jun 30, 2017
1451-1475 of 1973