The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
TitleEitWModules
CVE-2026-81543: Tyche Softwares Abandoned Cart Pro for WooCommerce: The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up…8.8 HighN/AN/ASep 5, 2026
CVE-2026-83625: supsysticcom Contact Form by Supsystic: The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header…7.2 HighN/AN/ASep 5, 2026
CVE-2026-75018: outlawgt Custom Contact Forms: The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and…4.3 MediumN/AN/ASep 5, 2026
CVE-2026-85414: fooplugins Gallery : FooGallery: The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings'…6.4 MediumN/AN/ASep 5, 2026
CVE-2026-75586: unitecms Unlimited Elements For Elementor: The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via…6.1 MediumN/AN/ASep 5, 2026
CVE-2026-84937: Unknown Video Player for YouTube: The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input…N/AN/AN/ASep 5, 2026
CVE-2026-84936: Unknown EmbedPress: The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action,…N/AN/AN/ASep 5, 2026
CVE-2026-84935: Unknown HT Menu: The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving…N/AN/AN/ASep 5, 2026
CVE-2026-84934: Unknown JCH Optimize: The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX…N/AN/AN/ASep 5, 2026
CVE-2026-84931: Unknown Joli Table Of Contents: The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before…N/AN/AN/ASep 5, 2026
CVE-2026-84930: Unknown CatFolders Document Gallery & PDF Library: The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block…N/AN/AN/ASep 5, 2026
CVE-2026-84927: Unknown EmbedPress: The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google…N/AN/AN/ASep 5, 2026
CVE-2026-84926: Unknown EmbedPress: The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST…N/AN/AN/ASep 5, 2026
CVE-2026-84901: Unknown Eventin: The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management…N/AN/AN/ASep 5, 2026
CVE-2026-84899: Unknown VikWidgetsLoader: The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it…N/AN/AN/ASep 5, 2026
CVE-2026-84898: Unknown Eventin: The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include…N/AN/AN/ASep 5, 2026
CVE-2026-84896: Unknown King Addons for Elementor: The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before…N/AN/AN/ASep 5, 2026
CVE-2026-84745: Unknown The Events Calendar: The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read…N/AN/AN/ASep 5, 2026
CVE-2026-84225: Unknown Kirki: The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before…N/AN/AN/ASep 5, 2026
CVE-2026-84221: Unknown Kirki: The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query,…N/AN/AN/ASep 5, 2026
CVE-2026-84022: Unknown Bold Page Builder: The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before…N/AN/AN/ASep 5, 2026
CVE-2026-84021: Unknown Bold Page Builder: The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an…N/AN/AN/ASep 5, 2026
CVE-2026-83544: Unknown Greenshift: The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it…N/AN/AN/ASep 5, 2026
CVE-2026-83543: Unknown Greenshift: The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side,…N/AN/AN/ASep 5, 2026
CVE-2026-82846: Unknown Masteriyo LMS: The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting…N/AN/AN/ASep 5, 2026
1-25 of 385942