The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-87911: OS Command Injection9.6 Critical9.0 CriticalN/ASep 9, 2026
CVE-2026-79324: n/a: Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through…7.5 HighN/AN/ASep 9, 2026
CVE-2026-73789: Hewlett Packard Enterprise (HPE) ClearPass Policy Manager (CPPM): A vulnerability in the web-based management interface of CPPM guest account management services could allow an…5.3 MediumN/AN/ASep 9, 2026
CVE-2026-73788: Hewlett Packard Enterprise (HPE) ClearPass Policy Manager (CPPM): A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own…6.5 MediumN/AN/ASep 9, 2026
CVE-2026-73787: Hewlett Packard Enterprise (HPE) ClearPass Policy Manager (CPPM): A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information…7.2 HighN/AN/ASep 9, 2026
CVE-2026-73786: Hewlett Packard Enterprise (HPE) ClearPass Policy Manager (CPPM): A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct…7.5 HighN/AN/ASep 9, 2026
CVE-2026-73769: Hewlett Packard Enterprise (HPE) ClearPass Policy Manager (CPPM): A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote…7.2 HighN/AN/ASep 9, 2026
CVE-2026-71616: n/a: An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the…N/AN/AN/ASep 9, 2026
CVE-2026-71614: An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the…N/AN/AN/ASep 9, 2026
CVE-2026-71613: Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary…N/AN/AN/ASep 9, 2026
CVE-2026-71612: n/a: Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary…N/AN/AN/ASep 9, 2026
CVE-2026-61915: cyrusimap Cyrus IMAP: An issue was discovered in Cyrus IMAP before 3.12.44.2 MediumN/AN/ASep 9, 2026
CVE-2026-61911: cyrusimap Cyrus IMAP: An issue was discovered in Cyrus IMAP before 3.12.44.3 MediumN/AN/ASep 9, 2026
CVE-2026-61910: An issue was discovered in Cyrus IMAP before 3.12.43.5 LowN/AN/ASep 9, 2026
CVE-2026-61909: cyrusimap Cyrus IMAP: An issue was discovered in Cyrus IMAP before 3.12.43.5 LowN/AN/ASep 9, 2026
CVE-2026-61908: cyrusimap Cyrus IMAP: An issue was discovered in Cyrus IMAP before 3.12.43.1 LowN/AN/ASep 9, 2026
CVE-2026-38998: n/a: A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming…N/AN/AN/ASep 9, 2026
CVE-2026-79323: Exposure of Sensitive Information7.5 HighN/AN/ASep 9, 2026
CVE-2026-79322: SQL Injection8.6 HighN/AN/ASep 9, 2026
CVE-2026-61907: An issue was discovered in Cyrus IMAP before 3.12.44.3 MediumN/AN/ASep 9, 2026
CVE-2026-54694: NationalSecurityAgency skills-service: SkillTree is a micro-learning gamification platform9.6 CriticalN/AN/ASep 9, 2026
CVE-2026-52482: An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via…N/AN/AN/ASep 9, 2026
CVE-2026-39020: n/a: An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file5.5 MediumN/AN/ASep 9, 2026
CVE-2025-51619: n/a: A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to…5.5 MediumN/AN/ASep 9, 2026
CVE-2026-8044: Schneider Electric EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert): CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that…N/A8.6 HighN/ASep 9, 2026
1-25 of 421798