The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-93655: wpdevelop Booking Calendar: The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill'…6.1 MediumN/AN/ASep 22, 2026
CVE-2026-12470: niteo CMP – Coming Soon & Maintenance Plugin by NiteoThemes: The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized…7.2 HighN/AN/ASep 22, 2026
CVE-2026-85653: ajay Contextual Related Posts: The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes'…6.4 MediumN/AN/ASep 22, 2026
CVE-2026-19658: LiquidWeb Give Tributes: The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,…9.8 CriticalN/AN/ASep 22, 2026
CVE-2026-13355: Meta Box Meta Box Frontend Submission: The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and…9.8 CriticalN/AN/ASep 22, 2026
CVE-2026-94493: Gigatech PDV5701: A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_11264010.0 Critical9.3 CriticalN/ASep 22, 2026
CVE-2026-94492: Yonyou U8cloud: A security vulnerability has been detected in Yonyou U8cloud 5.x6.3 Medium2.1 LowN/ASep 22, 2026
CVE-2026-94491: Yonyou KSOA: A weakness has been identified in Yonyou KSOA 9.07.3 High5.5 MediumN/ASep 22, 2026
CVE-2026-93712: Path TraversalN/AN/AN/ASep 22, 2026
CVE-2026-93711: HTTP Response SplittingN/AN/AN/ASep 22, 2026
CVE-2026-93710: Improper Cleanup on Thrown ExceptionN/AN/AN/ASep 22, 2026
CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the…N/AN/AN/ASep 22, 2026
CVE-2026-76974: SAP_SE SAP Fiori Launchpad: SAP Fiori Launchpad does not sufficiently validate certain user-controlled input5.3 MediumN/AN/ASep 22, 2026
CVE-2026-94490: n/a OctoPrint: A security flaw has been discovered in OctoPrint 1.0.04.7 Medium2.0 LowN/ASep 22, 2026
CVE-2026-94489: n/a OctoPrint: A vulnerability was identified in OctoPrint 1.0.04.3 Medium2.1 LowN/ASep 22, 2026
CVE-2026-94426: xuxueli xxl-job: A vulnerability was determined in xuxueli xxl-job up to 3.5.03.5 Low2.0 LowN/ASep 21, 2026
CVE-2026-94425: Moore Threads MTT S80 Driver Package: A vulnerability was found in Moore Threads MTT S80 Driver Package 340.1508.8 High9.3 CriticalN/ASep 21, 2026
CVE-2026-94627: vllm-project vllm: vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child…7.5 High8.7 HighN/ASep 21, 2026
CVE-2026-94626: vllm-project vllm: vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion…7.5 High8.7 HighN/ASep 21, 2026
CVE-2026-94625: vllm-project vllm: vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests…5.3 Medium6.9 MediumN/ASep 21, 2026
CVE-2026-94624: vllm-project vllm: vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is…7.5 High8.7 HighN/ASep 21, 2026
CVE-2026-94623: vllm-project vllm: vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation…7.5 High8.7 HighN/ASep 21, 2026
CVE-2026-94622: vllm-project vllm: vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for…7.5 High8.7 HighN/ASep 21, 2026
CVE-2026-94540: MrPear DesktopSMS: DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS,…7.7 High7.4 HighN/ASep 21, 2026
CVE-2026-94536: dromara lamp-cloud: lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing…4.3 Medium5.3 MediumN/ASep 21, 2026
1-25 of 691462