The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
TitleEitWModules
CVE-2026-16654: themefusion Avada (Fusion) Builder: The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode…6.4 MediumN/AN/AAug 28, 2026
CVE-2026-18983: onedesigns One User Avatar | User Profile Picture: The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all…7.5 HighN/AN/AAug 28, 2026
CVE-2026-3129: litespeedtech LiteSpeed Cache: The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag…6.4 MediumN/AN/AAug 28, 2026
CVE-2026-16759: themeum Tutor LMS – eLearning and online course solution: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution…6.5 MediumN/AN/AAug 28, 2026
CVE-2026-18324: wpmudev: The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored…7.2 HighN/AN/AAug 28, 2026
CVE-2026-18978: litespeedtech LiteSpeed Cache: The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all…7.2 HighN/AN/AAug 28, 2026
CVE-2026-82090: getpocket Pocket: Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOMN/A9.2 CriticalN/AAug 28, 2026
CVE-2026-82089: wallabag android-app: The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries…N/A8.8 HighN/AAug 28, 2026
CVE-2026-82082: Green-Computing NUMail: NUMail developed by Green-Computing has an OS Command Injection vulnerability9.8 Critical9.3 CriticalN/AAug 28, 2026
CVE-2026-82081: wallabag: wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.6.4 MediumN/AN/AAug 28, 2026
CVE-2026-15798: nextendweb Smart Slider 3: The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in…6.4 MediumN/AN/AAug 28, 2026
CVE-2026-77365: optimole Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization: The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is…7.2 HighN/AN/AAug 28, 2026
CVE-2026-76053: cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored…7.2 HighN/AN/AAug 28, 2026
CVE-2026-82072: Google Chrome: Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code…N/AN/AN/AAug 28, 2026
CVE-2026-81851: WatchGuard Fireware OS: A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash…N/A6.9 MediumN/AAug 28, 2026
CVE-2026-81848: cyberchitta scrapling-fetch-mcp: A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.23.5 Low5.1 MediumN/AAug 28, 2026
CVE-2026-81847: MAA-AI MaaMCP: A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a412875.5 Medium2.0 LowN/AAug 28, 2026
CVE-2026-81845: arben-adm mcp-sequential-thinking: A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.06.3 Medium2.1 LowN/AAug 28, 2026
CVE-2026-81837: RooCodeInc Roo-Code: A flaw has been found in RooCodeInc Roo-Code up to 3.51.16.3 Medium2.1 LowN/AAug 28, 2026
CVE-2026-81836: RooCodeInc Roo-Code: A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.13.7 Low2.9 LowN/AAug 28, 2026
CVE-2026-81835: RooCodeInc Roo-Code: A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.15.5 Medium2.0 LowN/AAug 28, 2026
CVE-2026-80179: Red Hat: A flaw was found in jwcrypto5.9 MediumN/AN/AAug 28, 2026
CVE-2026-78239: Xiiaozet Xiiaozet LK100W: Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote…9.8 Critical9.3 CriticalN/AAug 28, 2026
CVE-2026-78037: Xiiaozet Xiiaozet LK100W: Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface8.8 High8.7 HighN/AAug 28, 2026
CVE-2026-77977: Ebyte Ebyte NE2-D11 Firmware: Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive…8.1 High7.2 HighN/AAug 28, 2026
1-25 of 383656