The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2010-2695: Improper Limitation of a Pathname to a Restricted DirectoryN/AN/A2%Jul 12, 2010
CVE-2010-2305: Improper Restriction of Operations within the Bounds of a Memory BufferN/AN/A20%Jun 16, 2010
CVE-2009-4845: Undefined Security Weakness5.3 MediumN/A1%May 7, 2010
CVE-2009-4510: Undefined Security Weakness8.1 HighN/A2%Apr 13, 2010
CVE-2010-0500: Improper Input Validation7.5 HighN/A2%Mar 30, 2010
CVE-2010-0168: Undefined Security Weakness8.8 HighN/A12%Mar 25, 2010
CVE-2010-0137: Undefined Security Weakness7.5 HighN/A3%Jan 21, 2010
CVE-2009-3702: Improper Limitation of a Pathname to a Restricted DirectoryN/AN/A2%Dec 22, 2009
CVE-2009-3304: Improper Link Resolution Before File Access4.4 MediumN/A0%Dec 4, 2009
CVE-2009-4075: Undefined Security WeaknessN/AN/A3%Nov 25, 2009
CVE-2009-2829: Undefined Security Weakness7.5 HighN/A2%Nov 10, 2009
CVE-2009-2818: Undefined Security Weakness5.3 MediumN/A2%Nov 10, 2009
CVE-2009-3710: Undefined Security Weakness9.8 CriticalN/A8%Oct 16, 2009
CVE-2009-3542: Improper Limitation of a Pathname to a Restricted Directory7.3 HighN/A2%Oct 2, 2009
CVE-2009-2904: Undefined Security Weakness7.1 HighN/A0%Oct 1, 2009
CVE-2009-2871: Undefined Security Weakness7.5 HighN/A3%Sep 28, 2009
CVE-2009-3340: Undefined Security Weakness5.3 MediumN/A1%Sep 24, 2009
CVE-2009-3369: Undefined Security Weakness8.1 HighN/A3%Sep 24, 2009
CVE-2008-7225: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A5%Sep 14, 2009
CVE-2008-7031: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A8%Aug 24, 2009
CVE-2008-6899: Improper Restriction of Operations within the Bounds of a Memory Buffer8.8 HighN/A5%Aug 5, 2009
CVE-2009-2410: Improper Authentication7.3 HighN/A2%Jul 30, 2009
CVE-2009-1165: Undefined Security Weakness7.5 HighN/A2%Jul 29, 2009
CVE-2009-2465: Undefined Security Weakness8.8 HighN/A5%Jul 22, 2009
CVE-2009-2263: Improper Limitation of a Pathname to a Restricted Directory7.3 HighN/A2%Jun 30, 2009
1726-1750 of 1974