The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-19986: Improper Authorization5.4 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19984: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19983: Improper Neutralization of Special Elements used in an OS Command8.3 High6.9 Medium1%Aug 17, 2026
CVE-2026-19982: Improper Neutralization of Special Elements used in an OS Command7.4 High5.3 Medium1%Aug 17, 2026
CVE-2026-19981: Improper Neutralization of Special Elements used in an OS Command7.4 High5.3 Medium1%Aug 17, 2026
CVE-2026-19980: Improper Control of Generation of Code7.4 High5.3 Medium0%Aug 17, 2026
CVE-2026-19979: Authorization Bypass Through User-Controlled Key8.3 High6.9 Medium0%Aug 17, 2026
CVE-2026-19978: Improper Neutralization of Special Elements used in an OS Command5.3 Medium1.9 Low1%Aug 17, 2026
CVE-2026-50602: Incorrect Permission Assignment for Critical ResourceN/A8.5 High0%Aug 17, 2026
CVE-2026-50601: Use of Hard-coded CredentialsN/A6.6 Medium0%Aug 17, 2026
CVE-2026-19977: Improper Authentication10.0 Critical9.3 Critical1%Aug 17, 2026
CVE-2026-19976: Improper Neutralization of Special Elements used in a Command6.6 Medium2.0 Low2%Aug 17, 2026
CVE-2026-19975: Time-of-check Time-of-use (TOCTOU) Race Condition3.1 Low1.3 Low0%Aug 17, 2026
CVE-2026-19974: Improper Authentication5.6 Medium2.9 Low0%Aug 17, 2026
CVE-2026-19973: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19972: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19971: Missing Authentication for Critical Function4.7 Medium5.3 Medium0%Aug 17, 2026
CVE-2026-19970: Heap-based Buffer Overflow6.3 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19969: Buffer Copy without Checking Size of Input5.4 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19968: Heap-based Buffer Overflow4.3 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19967: Heap-based Buffer Overflow6.3 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19966: Authorization Bypass Through User-Controlled Key5.4 Medium2.1 Low0%Aug 17, 2026
CVE-2026-19965: Observable Response Discrepancy3.7 Low2.9 Low0%Aug 17, 2026
CVE-2026-19964: Improper Control of Generation of Code5.5 Medium2.0 Low0%Aug 17, 2026
CVE-2026-19963: Improper Neutralization of Special Elements used in a Command7.4 High2.1 Low1%Aug 17, 2026
17251-17275 of 612018