The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
TitleEitWModules
CVE-2026-83743: invoiceninja Invoice Ninja: A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.266.3 Medium5.3 MediumN/ASep 1, 2026
CVE-2026-19948: cozythemes: The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for…5.3 MediumN/AN/ASep 1, 2026
CVE-2026-77823: thimpress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv…4.9 MediumN/AN/ASep 1, 2026
CVE-2026-12747: shabti Frontend Admin by DynamiApps: The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode…6.4 MediumN/AN/ASep 1, 2026
CVE-2026-19573: worschtebrot Affiliate Super Assistent: The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…7.2 HighN/AN/ASep 1, 2026
CVE-2026-13203: livecomposer Live Composer – Free WordPress Website Builder: The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting…6.4 MediumN/AN/ASep 1, 2026
CVE-2026-16787: livecomposer Live Composer – Free WordPress Website Builder: The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting…6.4 MediumN/AN/ASep 1, 2026
CVE-2026-76006: ays-pro Photo Gallery by Ays – Responsive Image Gallery: The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the…4.9 MediumN/AN/ASep 1, 2026
CVE-2026-19952: shabti Frontend Admin by DynamiApps: The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file…7.5 HighN/AN/ASep 1, 2026
CVE-2026-75965: cozmoslabs: The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is…6.4 MediumN/AN/ASep 1, 2026
CVE-2026-18752: lukeseager Persistent Login: The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all…6.5 MediumN/AN/ASep 1, 2026
CVE-2026-17589: levelfourstorefront Shopping Cart & eCommerce Store: The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order'…4.9 MediumN/AN/ASep 1, 2026
CVE-2026-19806: devitemsllc: The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is…8.8 HighN/AN/ASep 1, 2026
CVE-2026-75921: pixarlabs: The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder &…7.2 HighN/AN/ASep 1, 2026
CVE-2026-19796: webilia Listdom: AI-powered Business Directory with Classifieds Ads Listings: The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored…7.2 HighN/AN/ASep 1, 2026
CVE-2026-82749: ash-project ash: Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match…N/A5.9 MediumN/ASep 1, 2026
CVE-2026-82748: ash-project ash: Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing…N/A2.1 LowN/ASep 1, 2026
CVE-2026-82746: ash-project ash: Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies…N/A5.9 MediumN/ASep 1, 2026
CVE-2026-82745: ash-project ash: Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS…N/A5.9 MediumN/ASep 1, 2026
CVE-2026-82744: ash-project ash: Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard…N/A2.1 LowN/ASep 1, 2026
CVE-2026-82743: ash-project ash: Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler…N/A2.1 LowN/ASep 1, 2026
CVE-2026-82742: ash-project ash: Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node memory by matching a…N/A5.9 MediumN/ASep 1, 2026
CVE-2026-82741: ash-project ash: Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored…N/A2.1 LowN/ASep 1, 2026
CVE-2026-82740: ash-project ash: Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a…N/A2.1 LowN/ASep 1, 2026
CVE-2026-82739: ash-project ash: Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored…N/A2.1 LowN/ASep 1, 2026
1-25 of 527928