The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2017-5243: Use of a Broken or Risky Cryptographic Algorithm8.5 HighN/A1%Jun 6, 2017
CVE-2015-0936: Undefined Security Weakness9.8 CriticalN/A78%Jun 1, 2017
CVE-2017-6131: Use of Hard-coded Credentials9.8 CriticalN/A1%May 23, 2017
CVE-2017-9137: Initialization of a Resource with an Insecure Default7.3 HighN/A1%May 21, 2017
CVE-2017-9079: Incorrect Permission Assignment for Critical Resource4.7 MediumN/A0%May 19, 2017
CVE-2015-9057: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%May 3, 2017
CVE-2017-6128: Undefined Security Weakness7.5 HighN/A1%May 1, 2017
CVE-2017-8109: Exposure of Sensitive Information to an Unauthorized Actor7.8 HighN/A0%Apr 25, 2017
CVE-2016-1561: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A74%Apr 21, 2017
CVE-2016-1560: Use of Hard-coded Credentials9.8 CriticalN/A72%Apr 21, 2017
CVE-2017-7722: Improper Neutralization of Special Elements used in a Command10.0 CriticalN/A13%Apr 12, 2017
CVE-2016-1908: Improper Authentication9.8 CriticalN/A14%Apr 11, 2017
CVE-2015-7272: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A3%Apr 10, 2017
CVE-2017-3834: Initialization of a Resource with an Insecure Default9.8 CriticalN/A4%Apr 6, 2017
CVE-2017-3204: Undefined Security Weakness8.1 HighN/A3%Apr 4, 2017
CVE-2014-3929: Improper Access Control7.5 HighN/A2%Apr 3, 2017
CVE-2016-8754: Use of Hard-coded Credentials7.5 HighN/A0%Apr 2, 2017
CVE-2014-8572: Improper Input Validation7.5 HighN/A1%Apr 2, 2017
CVE-2014-3221: Undefined Security Weakness7.5 HighN/A1%Apr 2, 2017
CVE-2016-10308: Use of Hard-coded Credentials9.8 CriticalN/A3%Mar 30, 2017
CVE-2016-10307: Use of Hard-coded Credentials9.8 CriticalN/A2%Mar 30, 2017
CVE-2016-10306: Use of Hard-coded Credentials9.8 CriticalN/A3%Mar 30, 2017
CVE-2016-10305: Use of Hard-coded Credentials9.8 CriticalN/A2%Mar 30, 2017
CVE-2017-6542: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A22%Mar 27, 2017
CVE-2016-4927: Improper Input Validation8.1 HighN/A1%Mar 20, 2017
1476-1500 of 1973