The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
TitleEitWModules
CVE-2026-82343: Red Hat: A flaw was found in the file-psd plugin in GIMP6.1 MediumN/AN/AAug 28, 2026
CVE-2026-82329: jfrog artifactory: JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated…9.8 CriticalN/AN/AAug 28, 2026
CVE-2026-82306: starrocks: StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns…6.5 MediumN/AN/AAug 28, 2026
CVE-2026-82291: heyform: HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling…8.1 HighN/AN/AAug 28, 2026
CVE-2026-82290: chainlit: Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints5.3 Medium6.0 MediumN/AAug 28, 2026
CVE-2026-82289: coderamp-labs gitingest: Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git.,…7.4 High8.3 HighN/AAug 28, 2026
CVE-2026-82288: AUTOMATIC1111 stable-diffusion-webui: Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags…7.5 High8.7 HighN/AAug 28, 2026
CVE-2026-82287: rybbit-io rybbit: Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions…8.1 High8.6 HighN/AAug 28, 2026
CVE-2026-82286: BuilderIO gpt-crawler: gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing…8.6 High8.8 HighN/AAug 28, 2026
CVE-2026-82285: dataelement bisheng: bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST…8.2 High8.8 HighN/AAug 28, 2026
CVE-2026-82284: QuivrHQ quivr: Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE…8.1 High8.6 HighN/AAug 28, 2026
CVE-2026-82283: voltagent: VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users…8.1 High8.6 HighN/AAug 28, 2026
CVE-2026-82282: runatlantis atlantis: Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to…8.0 High8.8 HighN/AAug 28, 2026
CVE-2026-82281: Cinnamon kotaemon: Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and…7.4 High9.1 CriticalN/AAug 28, 2026
CVE-2026-82280: QuivrHQ quivr: Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any…7.1 High7.1 HighN/AAug 28, 2026
CVE-2026-82279: hyperdxio hyperdx: HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team…8.1 High7.2 HighN/AAug 28, 2026
CVE-2026-82278: dataelement bisheng: BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows…8.8 High8.7 HighN/AAug 28, 2026
CVE-2026-82277: argoproj argo-rollouts: Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without…9.8 Critical9.3 CriticalN/AAug 28, 2026
CVE-2026-82276: starrocks: StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override…5.3 MediumN/AN/AAug 28, 2026
CVE-2026-82275: QwenLM Qwen-Agent: Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file…7.5 High8.7 HighN/AAug 28, 2026
CVE-2026-82274: twentyhq twenty: Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback…4.7 Medium5.3 MediumN/AAug 28, 2026
CVE-2026-82273: mastra-ai mastra: Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation…6.5 Medium7.1 HighN/AAug 28, 2026
CVE-2026-82272: immich-app immich: Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset…6.5 Medium7.1 HighN/AAug 28, 2026
CVE-2026-82271: SciPhi-AI R2R: R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing…6.5 Medium7.1 HighN/AAug 28, 2026
CVE-2026-82270: Portkey-AI gateway: Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that…7.5 High8.7 HighN/AAug 28, 2026
1-25 of 385729