The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
TitleEitWModules
CVE-2026-9055: melograno Booking for Appointments and Events Calendar – Amelia: The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege…9.8 CriticalN/AN/ASep 2, 2026
CVE-2025-46418: Westermo WeOS: Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.7.6 HighN/AN/ASep 2, 2026
CVE-2024-35585: Oxford Nanopore MinKNOW: Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.8.6 HighN/AN/ASep 2, 2026
CVE-2026-3851: Elegant Themes Divi: The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON…6.4 MediumN/AN/ASep 2, 2026
CVE-2026-19754: Baserow: Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula functionN/A8.6 HighN/ASep 2, 2026
CVE-2026-84442: MapQuest Get Directions App: A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android4.4 Medium1.9 LowN/ASep 2, 2026
CVE-2026-84441: n/a Piwigo: A security vulnerability has been detected in Piwigo up to 16.3.07.3 High5.5 MediumN/ASep 2, 2026
CVE-2026-14982: JoomUnited WP File Download: The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…8.1 HighN/AN/ASep 2, 2026
CVE-2026-14957: The Libreswan Project libreswan: In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not…7.5 HighN/AN/ASep 2, 2026
CVE-2026-84715: MythicalLTD FeatherPanel: FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler,…8.8 High8.7 HighN/ASep 2, 2026
CVE-2026-84485: apitable: APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing…7.5 High8.7 HighN/ASep 2, 2026
CVE-2026-84484: nasa-jpl ION-DTN: ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows…7.5 High8.7 HighN/ASep 2, 2026
CVE-2026-84438: n/a OpenCart: A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.43.5 Low2.0 LowN/ASep 2, 2026
CVE-2026-84437: n/a OpenCart: A vulnerability was found in OpenCart 4.1.0.3/4.1.0.43.5 Low2.0 LowN/ASep 2, 2026
CVE-2026-84431: AirAsia MOVE App: A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android4.4 Medium1.9 LowN/ASep 2, 2026
CVE-2026-82968: Red Hat: A flaw was found in the first-broker-login flow of the Keycloak identity management service6.4 MediumN/AN/ASep 2, 2026
CVE-2026-84427: zhayujie CowAgent: A vulnerability was determined in zhayujie CowAgent up to 2.1.74.3 Medium2.1 LowN/ASep 2, 2026
CVE-2026-84425: zhayujie CowAgent: A vulnerability was found in zhayujie CowAgent up to 2.1.34.3 Medium2.1 LowN/ASep 2, 2026
CVE-2026-84430: n/a gouguoa: A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.16.3 Medium2.1 LowN/ASep 2, 2026
CVE-2026-84702: facefusion: facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files…7.5 High8.7 HighN/ASep 2, 2026
CVE-2026-84701: nocobase: NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store…5.4 Medium5.1 MediumN/ASep 2, 2026
CVE-2026-84700: OpenAtomFoundation pikiwidb: PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000…8.6 High8.8 HighN/ASep 2, 2026
CVE-2026-84699: Team Password Manager: Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password…9.1 Critical9.3 CriticalN/ASep 2, 2026
CVE-2026-84698: PX4 PX4-Autopilot: PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block…6.5 Medium7.1 HighN/ASep 2, 2026
CVE-2026-84697: axllent mailpit: Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC…5.3 Medium6.9 MediumN/ASep 2, 2026
1-25 of 762452