The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-59309:Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
TitleEitWModules
CVE-2026-18556: N-able N-central: Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication BypassN/A8.2 HighN/AAug 1, 2026
CVE-2026-55735: ueberauth guardian: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a…N/A8.2 HighN/AAug 1, 2026
CVE-2026-55734: ueberauth guardian: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module)…N/A6.9 MediumN/AAug 1, 2026
CVE-2026-55733: ueberauth guardian: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom…N/A6.9 MediumN/AAug 1, 2026
CVE-2026-54894: ueberauth guardian: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom…N/A6.9 MediumN/AAug 1, 2026
CVE-2026-67355: guzzle: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the…5.9 Medium8.2 HighN/AAug 1, 2026
CVE-2026-67354: guzzle: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware5.9 Medium8.2 HighN/AAug 1, 2026
CVE-2026-67353: guzzle: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts…5.3 Medium6.9 MediumN/AAug 1, 2026
CVE-2026-67352: openwrt luci: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows…7.6 High6.8 MediumN/AAug 1, 2026
CVE-2026-67344: ArcadeData arcadedb: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ..4.3 Medium8.5 HighN/AAug 1, 2026
CVE-2026-67343: ArcadeData arcadedb: ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing…8.8 High8.7 HighN/AAug 1, 2026
CVE-2026-67342: ArcadeData arcadedb: ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch,…9.8 Critical9.3 CriticalN/AAug 1, 2026
CVE-2026-67341: ArcadeData arcadedb: ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement…9.8 Critical9.3 CriticalN/AAug 1, 2026
CVE-2026-67340: ArcadeData arcadedb: ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type)…9.8 Critical9.3 CriticalN/AAug 1, 2026
CVE-2026-67339: guzzle: guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in…5.3 Medium6.9 MediumN/AAug 1, 2026
CVE-2026-67338: jupyterlab: JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to…6.1 Medium5.1 MediumN/AAug 1, 2026
CVE-2026-67337: better-auth: better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is…6.5 Medium7.1 HighN/AAug 1, 2026
CVE-2026-67336: better-auth: better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that…8.7 High9.4 CriticalN/AAug 1, 2026
CVE-2026-67335: better-auth: better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using…5.3 Medium6.0 MediumN/AAug 1, 2026
CVE-2026-67334: better-auth: better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM…3.8 Low5.1 MediumN/AAug 1, 2026
CVE-2026-67333: better-auth: better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of…7.2 High5.1 MediumN/AAug 1, 2026
CVE-2026-67332: better-auth oauth-provider: @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant,…6.4 Medium5.3 MediumN/AAug 1, 2026
CVE-2026-67331: better-auth scim: better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator…8.3 High8.7 HighN/AAug 1, 2026
CVE-2026-67330: better-auth scim: @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <=…9.9 Critical9.4 CriticalN/AAug 1, 2026
CVE-2026-67329: better-auth stripe: @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization…7.1 High7.1 HighN/AAug 1, 2026
1-25 of 372468