The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-93015: BlueKitchen GmbH BTstack: BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP…6.3 Medium7.0 HighN/ASep 17, 2026
CVE-2026-93014: RosarioSIS: RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing…7.1 High7.1 HighN/ASep 17, 2026
CVE-2026-93013: infiniflow ragflow: RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and…4.3 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-92881: n/a vgmstream: A security vulnerability has been detected in vgmstream4.3 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-91039: team-alembic ash_authentication: Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one…N/A9.1 CriticalN/ASep 17, 2026
CVE-2026-89036: appwrite: Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write…8.8 High8.7 HighN/ASep 17, 2026
CVE-2026-86864: pgadmin.org pgAdmin 4: pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the…8.8 High8.7 HighN/ASep 17, 2026
CVE-2026-86863: pgadmin.org pgAdmin 4: pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse…9.8 Critical9.3 CriticalN/ASep 17, 2026
CVE-2026-86862: pgadmin.org pgAdmin 4: pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the…6.5 Medium7.1 HighN/ASep 17, 2026
CVE-2026-86861: pgadmin.org pgAdmin 4: pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested…5.9 Medium6.0 MediumN/ASep 17, 2026
CVE-2026-86040: libp2p, @libp2p: libp2p is a JavaScript implementation of the libp2p networking stack7.5 HighN/AN/ASep 17, 2026
CVE-2026-86039: libp2p js-libp2p: libp2p is a JavaScript implementation of the libp2p networking stack8.2 HighN/AN/ASep 17, 2026
CVE-2026-86038: libp2p js-libp2p: libp2p is a JavaScript implementation of the libp2p networking stack7.5 HighN/AN/ASep 17, 2026
CVE-2026-86000: facelessuser soupsieve: Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 45.3 MediumN/AN/ASep 17, 2026
CVE-2026-85999: facelessuser soupsieve: Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 45.3 MediumN/AN/ASep 17, 2026
CVE-2026-85721: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…7.5 HighN/AN/ASep 17, 2026
CVE-2026-85719: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…7.5 HighN/AN/ASep 17, 2026
CVE-2026-85718: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…5.9 MediumN/AN/ASep 17, 2026
CVE-2026-85717: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…6.8 MediumN/AN/ASep 17, 2026
CVE-2026-85715: mattiasw ExifReader: ExifReader is a JavaScript Exif information parser7.5 HighN/AN/ASep 17, 2026
CVE-2026-81868: SteeltoeOSS security-advisories: Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…6.5 MediumN/AN/ASep 17, 2026
CVE-2026-81516: SteeltoeOSS security-advisories: Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…7.5 HighN/AN/ASep 17, 2026
CVE-2026-81515: SteeltoeOSS security-advisories: Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…7.5 HighN/AN/ASep 17, 2026
CVE-2026-76834: b2evolution b2evolution CMS: b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array…8.1 High9.2 CriticalN/ASep 17, 2026
CVE-2026-76781: Red Hat: A flaw was found in libxml25.5 MediumN/AN/ASep 17, 2026
1-25 of 543158