The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
TitleEitWModules
CVE-2025-63927: Heap-based Buffer Overflow4.0 MediumN/A0%Nov 12, 2025
CVE-2025-64181: Use of Uninitialized Variable7.5 High2.0 Low0%Nov 10, 2025
CVE-2023-53726: Undefined Security Weakness7.1 HighN/A0%Oct 22, 2025
CVE-2025-40016: Undefined Security WeaknessN/AN/A0%Oct 20, 2025
CVE-2025-55085: Out-of-bounds Read7.5 High8.8 High0%Oct 17, 2025
CVE-2025-62410: Improperly Controlled Modification of Object Prototype AttributesN/A9.4 Critical0%Oct 15, 2025
CVE-2025-9336: Stack-based Buffer OverflowN/A6.8 Medium0%Oct 13, 2025
CVE-2022-50511: Undefined Security Weakness5.5 MediumN/A0%Oct 7, 2025
CVE-2023-53569: Undefined Security Weakness7.8 HighN/A0%Oct 4, 2025
CVE-2021-4460: Out-of-bounds Read7.1 HighN/A0%Oct 1, 2025
CVE-2023-53513: Uncontrolled Recursion5.5 MediumN/A0%Oct 1, 2025
CVE-2025-39897: NULL Pointer Dereference7.5 HighN/A0%Oct 1, 2025
CVE-2025-57349: Improperly Controlled Modification of Object Prototype Attributes7.5 HighN/A0%Sep 24, 2025
CVE-2025-39869: Out-of-bounds Read8.4 HighN/A0%Sep 23, 2025
CVE-2025-10456: Integer Overflow or Wraparound7.1 HighN/A0%Sep 19, 2025
CVE-2022-50390: Undefined Security Weakness5.5 MediumN/A0%Sep 18, 2025
CVE-2009-20005: Stack-based Buffer OverflowN/A9.3 Critical69%Sep 16, 2025
CVE-2025-39824: Use After Free7.8 HighN/A0%Sep 16, 2025
CVE-2025-39812: Use of Uninitialized Resource5.5 MediumN/A0%Sep 16, 2025
CVE-2025-10528: Protection Mechanism Failure7.3 HighN/A0%Sep 16, 2025
CVE-2025-39821: Out-of-bounds Write7.8 HighN/A0%Sep 16, 2025
CVE-2022-50332: Undefined Security Weakness5.5 MediumN/A0%Sep 15, 2025
CVE-2022-50287: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Sep 15, 2025
CVE-2023-53182: Undefined Security Weakness5.5 MediumN/A0%Sep 15, 2025
CVE-2025-41713: Initialization of a Resource with an Insecure Default6.5 MediumN/A0%Sep 15, 2025
151-175 of 489