The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-59309:Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
TitleEitWModules
CVE-2026-8325: Autodesk Revit: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability7.8 HighN/AN/AAug 6, 2026
CVE-2026-7867: Red Hat: A flaw was found in udisks27.8 HighN/AN/AAug 6, 2026
CVE-2026-7406: Autodesk: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer…7.8 HighN/AN/AAug 6, 2026
CVE-2026-7405: Autodesk: A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an…5.5 MediumN/AN/AAug 6, 2026
CVE-2026-71555: THM-Health PILOS: PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton4.1 MediumN/AN/AAug 6, 2026
CVE-2026-71554: python-hyper h2: h2 is a pure-Python implementation of a HTTP/2 protocol stack5.3 MediumN/AN/AAug 6, 2026
CVE-2026-71498: uhop node-re2: node-re2 provides RE2 regular expression bindings for Node.js5.1 MediumN/AN/AAug 6, 2026
CVE-2026-71497: jhy jsoup: jsoup is a Java library for working with real-world HTML4.7 MediumN/AN/AAug 6, 2026
CVE-2026-71488: thephpleague commonmark: league/commonmark is a PHP library for parsing and rendering CommonMark Markdown7.5 HighN/AN/AAug 6, 2026
CVE-2026-71478: thephpleague commonmark: league/commonmark is a PHP library for parsing and rendering CommonMark Markdown6.1 MediumN/AN/AAug 6, 2026
CVE-2026-71476: nrwl nx: Nx is a monorepo solution for TypeScript and polyglot codebasesN/A8.7 HighN/AAug 6, 2026
CVE-2026-71447: ail-project ail-framework: AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat…N/A6.9 MediumN/AAug 6, 2026
CVE-2026-71446: ail-project ail-framework: AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain viewN/A6.9 MediumN/AAug 6, 2026
CVE-2026-71445: ail-project ail-framework: AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpointN/A8.2 HighN/AAug 6, 2026
CVE-2026-71439: mermaid-js mermaid: Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and chartsN/A5.3 MediumN/AAug 6, 2026
CVE-2026-71438: mermaid-js mermaid: Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and chartsN/A2.4 LowN/AAug 6, 2026
CVE-2026-71437: mermaid-js mermaid: Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and chartsN/A6.5 MediumN/AAug 6, 2026
CVE-2026-71436: mermaid-js mermaid: Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and chartsN/A5.3 MediumN/AAug 6, 2026
CVE-2026-71435: statamic cms: Statamic is a Laravel and Git powered content management system (CMS)6.1 MediumN/AN/AAug 6, 2026
CVE-2026-71434: statamic cms: Statamic is a Laravel and Git powered content management system (CMS)5.3 MediumN/AN/AAug 6, 2026
CVE-2026-71433: langchain-ai: LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's…5.3 MediumN/AN/AAug 6, 2026
CVE-2026-71430: uhop node-re2: node-re2 provides RE2 regular expression bindings for Node.js6.2 MediumN/AN/AAug 6, 2026
CVE-2026-71327: traefik: Traefik is an open source HTTP reverse proxy and load balancerN/A7.6 HighN/AAug 6, 2026
CVE-2026-71326: traefik: Traefik is an open source HTTP reverse proxy and load balancerN/A2.1 LowN/AAug 6, 2026
CVE-2026-71325: traefik: Traefik is an open-source edge router that makes publishing services a fun and easy experienceN/A4.8 MediumN/AAug 6, 2026
1-25 of 374032