The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2014-7299: Undefined Security Weakness7.3 HighN/A2%Oct 8, 2014
CVE-2014-6603: Undefined Security Weakness5.3 MediumN/A3%Oct 7, 2014
CVE-2014-6278: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A100%Sep 30, 2014
CVE-2014-6751: Undefined Security Weakness5.0 MediumN/A0%Sep 28, 2014
CVE-2014-6277: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A70%Sep 27, 2014
CVE-2014-7169: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A100%Sep 25, 2014
CVE-2014-6271: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A100%Sep 24, 2014
CVE-2014-4826: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A1%Sep 18, 2014
CVE-2014-3348: Improper Input ValidationN/AN/A3%Sep 10, 2014
CVE-2014-5534: Undefined Security WeaknessN/AN/A0%Sep 9, 2014
CVE-2014-3563: Improper Link Resolution Before File Access7.8 HighN/A0%Aug 22, 2014
CVE-2014-4749: Undefined Security WeaknessN/AN/A1%Aug 20, 2014
CVE-2014-3486: Improper Link Resolution Before File Access7.8 HighN/A0%Jul 7, 2014
CVE-2014-2198: Undefined Security Weakness9.8 CriticalN/A4%Jul 7, 2014
CVE-2014-4152: Improper Control of Generation of Code9.8 CriticalN/A6%Jun 18, 2014
CVE-2014-0960: Undefined Security WeaknessN/AN/A1%Jun 14, 2014
CVE-2014-3048: Undefined Security Weakness7.0 HighN/A0%Jun 8, 2014
CVE-2013-1191: Undefined Security Weakness7.5 HighN/A2%May 24, 2014
CVE-2014-2200: Undefined Security Weakness7.5 HighN/A2%May 24, 2014
CVE-2013-4490: Undefined Security Weakness6.3 MediumN/A42%May 13, 2014
CVE-2013-4581: Improper Control of Generation of CodeN/AN/A2%May 12, 2014
CVE-2013-6372: Undefined Security Weakness5.5 MediumN/A0%May 8, 2014
CVE-2012-4638: Undefined Security Weakness5.5 MediumN/A0%Apr 23, 2014
CVE-2012-5014: Undefined Security Weakness6.5 MediumN/A1%Apr 23, 2014
CVE-2008-3277: Improper Limitation of a Pathname to a Restricted Directory5.3 MediumN/A0%Apr 15, 2014
1601-1625 of 1974