The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-59309:Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
TitleEitWModules
CVE-2026-14191: Out-of-bounds Write7.8 HighN/A1%Jul 1, 2026
CVE-2019-25677: Creation of Temporary File in Directory with Insecure Permissions5.5 Medium6.9 Medium0%Apr 5, 2026
CVE-2025-14111: Improper Limitation of a Pathname to a Restricted Directory5.0 Medium1.3 Low0%Dec 5, 2025
CVE-2025-52331: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 12, 2025
CVE-2025-8088: Path Traversal: '.../...//'8.8 High8.4 High95%Aug 8, 2025
CVE-2014-125119: Improper Input ValidationN/A8.4 High16%Jul 25, 2025
CVE-2025-6218: Improper Limitation of a Pathname to a Restricted Directory7.8 HighN/A6%Jun 21, 2025
CVE-2025-31334: Product UI does not Warn User of Unsafe Actions6.8 MediumN/A0%Apr 3, 2025
CVE-2024-36052: Improper Neutralization of Escape, Meta, or Control Sequences7.5 HighN/A0%May 21, 2024
CVE-2023-40477: Improper Validation of Array Index7.8 HighN/A93%May 3, 2024
CVE-2024-33899: Improper Neutralization of Escape, Meta, or Control Sequences7.1 HighN/A1%Apr 28, 2024
CVE-2024-30370: Protection Mechanism Failure4.3 MediumN/A0%Apr 2, 2024
CVE-2023-38831: Insufficient Verification of Data Authenticity7.8 HighN/A98%Aug 23, 2023
CVE-2022-43650: Out-of-bounds Read7.1 HighN/A2%Mar 29, 2023
CVE-2022-30333: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A99%May 9, 2022
CVE-2018-20253: Out-of-bounds Write7.8 HighN/A1%Feb 13, 2019
CVE-2018-20250: Absolute Path Traversal7.8 HighN/A93%Feb 5, 2019
CVE-2018-20251: Protection Mechanism Failure5.5 MediumN/A1%Feb 5, 2019
CVE-2018-20252: Out-of-bounds Write7.8 HighN/A1%Feb 5, 2019
CVE-2015-5663: Undefined Security Weakness7.4 HighN/A0%Dec 30, 2015
CVE-2008-7144: Undefined Security Weakness8.8 HighN/A1%Sep 1, 2009
CVE-2008-1835: Improper Input Validation4.3 MediumN/A2%Apr 16, 2008
CVE-2007-3726: Undefined Security Weakness5.5 MediumN/A1%Jul 12, 2007
CVE-2007-3122: Undefined Security Weakness7.1 HighN/A3%Jun 7, 2007
CVE-2007-0855: Undefined Security Weakness8.4 HighN/A6%Feb 8, 2007
1-25 of 60