The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-52691: Apache Software Foundation Apache Griffin Hive Metastore Module: ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…N/AN/AN/ASep 4, 2026
CVE-2026-85229: Apache Software Foundation Apache SkyWalking: ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting')…N/AN/A0%Sep 4, 2026
CVE-2026-80190: Apache Software Foundation Apache Allura: Apache Allura: stored XSS via SVN code repositories6.1 MediumN/A0%Sep 4, 2026
CVE-2026-81270: Apache Software Foundation Apache Allura: Apache Allura: exposure of non-public information via search7.5 HighN/A0%Sep 4, 2026
CVE-2026-80181: Apache Software Foundation Apache Allura: Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF)N/AN/A0%Sep 4, 2026
CVE-2026-80180: Apache Software Foundation Apache Allura: Stored XSS via markdown HTML processing in Apache Allura6.1 MediumN/A0%Sep 4, 2026
CVE-2026-71216: Apache Software Foundation Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTPN/AN/A0%Sep 4, 2026
CVE-2026-67402: WebPros, ConfigServer ConfigServer Security & Firewall: An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the…N/A9.2 Critical0%Sep 4, 2026
CVE-2026-49833: DSpace: DSpace open source software is a repository application which provides durable access to digital resources5.5 MediumN/A0%Sep 2, 2026
CVE-2026-10821: Unknown Yoast SEO Premium: The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before…6.6 MediumN/A1%Sep 2, 2026
CVE-2026-32773: Apache Software Foundation Apache Spark: There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to…6.1 MediumN/A0%Sep 2, 2026
CVE-2026-84218: Incomplete List of Disallowed Inputs8.1 HighN/A1%Sep 1, 2026
CVE-2026-11873: Generation of Error Message Containing Sensitive Information6.5 MediumN/A0%Sep 1, 2026
CVE-2026-75594: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.2 High1%Aug 31, 2026
CVE-2026-17615: Improper Restriction of XML External Entity Reference7.5 HighN/A0%Aug 31, 2026
CVE-2026-76986: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A1%Aug 31, 2026
CVE-2026-76985: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Aug 31, 2026
CVE-2026-12894: Improper Neutralization of Special Elements Used in a Template Engine8.8 HighN/A0%Aug 31, 2026
CVE-2026-76984: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Aug 31, 2026
CVE-2026-76983: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Aug 31, 2026
CVE-2026-76982: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Aug 31, 2026
CVE-2026-75802: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Aug 31, 2026
CVE-2026-71378: Cross-Site Request Forgery (CSRF)4.6 MediumN/A0%Aug 31, 2026
CVE-2026-71257: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Aug 31, 2026
CVE-2026-70449: Improper Limitation of a Pathname to a Restricted Directory5.3 MediumN/A1%Aug 31, 2026
1-25 of 3895