The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92616: error311 FileRise: FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege…6.8 Medium7.6 HighN/ASep 16, 2026
CVE-2026-92571: Rejected reason: CVE ID reserved in error and not assigned to a vulnerabilityN/AN/AN/ASep 16, 2026
CVE-2026-92570: yogeshojha rengine: reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows…6.5 Medium7.1 HighN/ASep 16, 2026
CVE-2026-92569: opengoofy hippo4j: Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that…4.3 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92568: mlrun: MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that…5.4 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92567: TDuckCloud tduck-survey-form: TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update…6.5 Medium7.1 HighN/ASep 16, 2026
CVE-2026-92566: datageartech datagear: DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that…8.2 High8.8 HighN/ASep 16, 2026
CVE-2026-92565: lukevella rallly: Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns…5.3 Medium6.9 MediumN/ASep 16, 2026
CVE-2026-92395: @fastify/proxy-addr: @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and…9.1 CriticalN/AN/ASep 16, 2026
CVE-2026-92383: n/a PbootCMS: A security vulnerability has been detected in PbootCMS up to 3.2.244.3 Medium2.1 LowN/ASep 16, 2026
CVE-2026-92381: n/a PbootCMS: A weakness has been identified in PbootCMS up to 3.2.223.5 Low2.0 LowN/ASep 16, 2026
CVE-2026-92380: n/a WuzhiCMS: A flaw has been found in WuzhiCMS up to 4.1.07.3 High5.5 MediumN/ASep 16, 2026
CVE-2026-92366: code-projects Matrimonial System: A vulnerability was determined in code-projects Matrimonial System 1.07.3 High5.5 MediumN/ASep 16, 2026
CVE-2026-92087: @fastify/auth: @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single…8.1 HighN/AN/ASep 16, 2026
CVE-2026-89031: Adenion Blog2Social: Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records…5.4 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-88976: udecode plate: Plate is a rich-text editor with AI and shadcn/ui6.1 MediumN/AN/ASep 16, 2026
CVE-2026-88064: backstage: Backstage is an open framework for building developer portals8.8 HighN/AN/ASep 16, 2026
CVE-2026-84997: reactphp http: react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP7.5 HighN/AN/ASep 16, 2026
CVE-2026-84860: Scada-LTS: ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by…8.8 HighN/AN/ASep 16, 2026
CVE-2026-84859: Scada-LTS: ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search…6.5 MediumN/AN/ASep 16, 2026
CVE-2026-84858: Scada-LTS: ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox…8.8 HighN/AN/ASep 16, 2026
CVE-2026-82964: Gen Digital: Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local,…8.8 HighN/AN/ASep 16, 2026
CVE-2026-82410: pocketbase: Pocketbase is an open source web backend written in goN/A8.7 HighN/ASep 16, 2026
CVE-2026-80274: ISC BIND 9: If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a…7.5 HighN/AN/ASep 16, 2026
CVE-2026-79651: Red Hat: A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service…7.5 HighN/AN/ASep 16, 2026
1-25 of 446145