The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-107812: 0xJacky nginx-ui: Nginx UI is a web user interface for the Nginx web server7.5 HighN/AN/AOct 9, 2026
CVE-2026-107783: AWS aws-tools-for-powershell: Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to…5.9 Medium6.7 MediumN/AOct 9, 2026
CVE-2026-107811: 0xJacky nginx-ui: Nginx UI is a web user interface for the Nginx web server8.8 HighN/AN/AOct 9, 2026
CVE-2026-107810: 0xJacky nginx-ui: Nginx UI is a web user interface for the Nginx web server8.1 HighN/AN/AOct 9, 2026
CVE-2026-90983: Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile: Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc8.2 HighN/AN/AOct 9, 2026
CVE-2026-107809: 0xJacky nginx-ui: Nginx UI is a web user interface for the Nginx web server8.8 HighN/AN/AOct 9, 2026
CVE-2026-78795: n/a: An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows…N/AN/AN/AOct 9, 2026
CVE-2026-39460: Red Lion Controls 700 Series: Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration…8.1 High9.3 CriticalN/AOct 9, 2026
CVE-2026-33367: Red Lion Controls 700 Series: SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or…8.1 High9.3 CriticalN/AOct 9, 2026
CVE-2026-32645: Red Lion Controls 700 Series: Default factory credentials with administrative access are enabled and persist even after configuring other…6.0 Medium9.2 CriticalN/AOct 9, 2026
CVE-2026-29797: Red Lion Controls 700 Series: No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to…7.1 High8.4 HighN/AOct 9, 2026
CVE-2026-28745: Red Lion Controls 700 Series: Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption7.5 High9.3 CriticalN/AOct 9, 2026
CVE-2026-108109: hotspotbilling phpnuxbill: PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in…9.1 Critical9.3 CriticalN/AOct 9, 2026
CVE-2026-108108: hotspotbilling phpnuxbill: PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because…7.1 High7.1 HighN/AOct 9, 2026
CVE-2026-108106: xerial snappy-java: Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to…7.5 High8.7 HighN/AOct 9, 2026
CVE-2026-108105: open5gs: Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows…5.9 Medium8.2 HighN/AOct 9, 2026
CVE-2026-108104: xerial snappy-java: Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream…4.8 Medium6.3 MediumN/AOct 9, 2026
CVE-2026-108103: open5gs: Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold()…5.3 Medium6.9 MediumN/AOct 9, 2026
CVE-2026-108101: danielbrendel hortusfox-web: HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that…7.5 High7.7 HighN/AOct 9, 2026
CVE-2026-108100: danielbrendel hortusfox-web: HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject…6.5 Medium7.1 HighN/AOct 9, 2026
CVE-2026-105278: Grid Protection Alliance openPDC (Docker image): The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use9.8 Critical9.3 CriticalN/AOct 9, 2026
CVE-2026-104117: illumos, OmniOS: A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the…N/A1.9 LowN/AOct 9, 2026
CVE-2026-104116: illumos, OmniOS: A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to…N/A1.9 LowN/AOct 9, 2026
CVE-2026-104115: illumos, OmniOS: A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemonN/A5.4 MediumN/AOct 9, 2026
CVE-2026-104114: illumos, OmniOS: A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemonN/A5.4 MediumN/AOct 9, 2026
1-25 of 402816
›