The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
TitleEitWModules
CVE-2026-73249: kovidgoyal calibre: calibre is an e-book manager7.5 HighN/AN/AAug 11, 2026
CVE-2026-73248: kovidgoyal calibre: calibre is an e-book managerN/A8.5 HighN/AAug 11, 2026
CVE-2026-73247: kestra-io kestra: Kestra is an open-source, event-driven orchestration platform8.6 HighN/AN/AAug 11, 2026
CVE-2026-73246: kestra-io kestra: Kestra is an open-source, event-driven orchestration platform7.5 HighN/AN/AAug 11, 2026
CVE-2026-73245: kestra-io kestra: Kestra is an open-source, event-driven orchestration platform6.5 MediumN/AN/AAug 11, 2026
CVE-2026-68067: Quanovate Tech Inc. (operating as Mira / Mira Care): The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live…9.8 Critical9.3 CriticalN/AAug 11, 2026
CVE-2026-67568: Quanovate Tech Inc. (operating as Mira / Mira Care): The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from…9.1 Critical9.3 CriticalN/AAug 11, 2026
CVE-2026-67558: Quanovate Tech Inc. (operating as Mira / Mira Care): The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match…7.4 High8.2 HighN/AAug 11, 2026
CVE-2026-66875: Quanovate Tech Inc. (operating as Mira / Mira Care): In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE…8.8 High8.7 HighN/AAug 11, 2026
CVE-2026-66340: Quanovate Tech Inc. (operating as Mira / Mira Care): The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout…5.3 Medium6.9 MediumN/AAug 11, 2026
CVE-2026-66098: Quanovate Tech Inc. (operating as Mira / Mira Care): The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the…6.5 Medium7.1 HighN/AAug 11, 2026
CVE-2026-64934: Quanovate Tech Inc. (operating as Mira / Mira Care): The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device,…4.3 Medium5.3 MediumN/AAug 11, 2026
CVE-2026-5917: libgit2: libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command…9.6 Critical9.4 CriticalN/AAug 11, 2026
CVE-2026-29036: DaveGamble cJSON: cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the…7.5 High8.7 HighN/AAug 11, 2026
CVE-2026-19560: Google Chrome: Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code…N/AN/AN/AAug 11, 2026
CVE-2026-19559: Google Chrome: Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code…N/AN/AN/AAug 11, 2026
CVE-2026-19558: Google Chrome: Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to…N/AN/AN/AAug 11, 2026
CVE-2026-19557: Google Chrome: Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had…N/AN/AN/AAug 11, 2026
CVE-2026-19556: Google Chrome: Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code…N/AN/AN/AAug 11, 2026
CVE-2026-18710: MongoDB MongoDB Driver: A MongoDB driver component could write sensitive configuration information, including a credential used for outbound…6.5 Medium8.2 HighN/AAug 11, 2026
CVE-2026-73250: notepad-plus-plus: Notepad++ is a free and open-source source code editorN/A5.4 MediumN/AAug 11, 2026
CVE-2026-71290: Apache Software Foundation Apache HttpComponents Client: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newerN/AN/AN/AAug 11, 2026
CVE-2026-66832: Quanovate Tech Inc. (operating as Mira / Mira Care): When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is…6.5 Medium6.9 MediumN/AAug 11, 2026
CVE-2026-66154: SonicWall GMS: An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application…8.3 HighN/AN/AAug 11, 2026
CVE-2026-66150: SonicWall Email Security: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance…7.8 HighN/AN/AAug 11, 2026
1-25 of 376092