The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2018-19077: Out-of-bounds Read7.5 HighN/A2%Nov 7, 2018
CVE-2018-13115: Improper Input Validation6.5 MediumN/A1%Oct 22, 2018
CVE-2018-18428: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A11%Oct 19, 2018
CVE-2018-4013: Out-of-bounds Write9.8 CriticalN/A10%Oct 19, 2018
CVE-2018-3856: Improper Neutralization of Argument Delimiters in a Command9.9 CriticalN/A3%Aug 23, 2018
CVE-2018-1000301: Out-of-bounds Read9.1 CriticalN/A6%May 24, 2018
CVE-2018-10328: Use of Hard-coded Credentials7.4 HighN/A1%Apr 24, 2018
CVE-2018-1000122: Out-of-bounds Read9.1 CriticalN/A9%Mar 14, 2018
CVE-2017-11633: Undefined Security Weakness7.5 HighN/A1%Feb 26, 2018
CVE-2017-15190: Undefined Security Weakness7.5 HighN/A2%Oct 10, 2017
CVE-2017-10796: Improper Authentication6.5 MediumN/A1%Jul 2, 2017
CVE-2017-8223: Improper Authentication7.5 HighN/A4%Apr 25, 2017
CVE-2016-3880: Improper Access Control5.5 MediumN/A1%Sep 11, 2016
CVE-2016-1262: Improper Input Validation5.9 MediumN/A2%Jan 15, 2016
CVE-2015-8040: Improper Input Validation7.3 HighN/A3%Nov 2, 2015
CVE-2015-1000: Improper Restriction of Operations within the Bounds of a Memory Buffer7.3 HighN/A3%Jun 5, 2015
CVE-2010-2062: Undefined Security Weakness9.8 CriticalN/A4%Dec 26, 2014
CVE-2014-4880: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A71%Dec 8, 2014
CVE-2014-6427: Improper Restriction of Operations within the Bounds of a Memory Buffer5.3 MediumN/A3%Sep 20, 2014
CVE-2013-4977: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A17%Mar 3, 2014
CVE-2013-4980: Improper Restriction of Operations within the Bounds of a Memory Buffer8.6 HighN/A6%Mar 3, 2014
CVE-2013-6933: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A17%Jan 23, 2014
CVE-2013-6934: Undefined Security Weakness7.3 HighN/A28%Jan 23, 2014
CVE-2013-3846: Undefined Security Weakness8.8 HighN/A22%Dec 29, 2013
CVE-2013-1606: Improper Restriction of Operations within the Bounds of a Memory BufferN/AN/A23%Jul 18, 2013
126-150 of 206