The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-63116: deepstreamIO deepstream.io: deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale8.8 HighN/AN/ASep 21, 2026
CVE-2026-62987: fabiolb fabio: Fabio is an HTTP(S) and TCP router for deploying applications managed by consul5.8 MediumN/AN/ASep 21, 2026
CVE-2026-62866: TomWright dasel: Dasel is a command-line tool and library for querying, modifying, and transforming data structures6.2 MediumN/AN/ASep 21, 2026
CVE-2026-62371: kubeedge: KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…8.8 HighN/AN/ASep 21, 2026
CVE-2026-62370: kubeedge: KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…6.5 MediumN/AN/ASep 21, 2026
CVE-2026-61674: fluent fluent-bit: Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and WindowsN/A9.2 CriticalN/ASep 21, 2026
CVE-2026-59168: TomWright dasel: Dasel is a command-line tool and library for querying, modifying, and transforming data structures6.2 MediumN/AN/ASep 21, 2026
CVE-2026-58504: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application6.1 MediumN/AN/ASep 21, 2026
CVE-2026-17051: zephyrproject zephyr: The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in…6.0 MediumN/AN/ASep 21, 2026
CVE-2026-17050: zephyrproject zephyr: The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the…5.7 MediumN/AN/ASep 21, 2026
CVE-2026-88978: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale4.3 MediumN/AN/ASep 21, 2026
CVE-2026-85751: Mailu: Mailu is a mail server distributed as a set of Docker images9.8 CriticalN/AN/ASep 21, 2026
CVE-2026-84298: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale3.1 LowN/AN/ASep 21, 2026
CVE-2026-82412: ntop ntopng: ntopng is a web-based network traffic monitoring application8.8 HighN/AN/ASep 21, 2026
CVE-2026-77166: Nextcloud Collectives: The emoji field in the page emoji update endpoint does not properly validate user input2.4 LowN/AN/ASep 21, 2026
CVE-2026-77165: Nextcloud Server: File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no…6.5 MediumN/AN/ASep 21, 2026
CVE-2026-63342: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale6.3 MediumN/AN/ASep 21, 2026
CVE-2026-61687: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale7.1 HighN/AN/ASep 21, 2026
CVE-2026-61681: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale4.1 MediumN/AN/ASep 21, 2026
CVE-2026-55563: feast-dev feast: Feast is the open source feature store for AI and machine learningN/A8.9 HighN/ASep 21, 2026
CVE-2026-53940: conda: Conda is a system-level binary package and environment manager that runs on major operating systems and platforms8.8 HighN/AN/ASep 21, 2026
CVE-2026-36472: n/a: CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS)5.2 MediumN/AN/ASep 21, 2026
CVE-2026-36471: n/a: Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote…N/AN/AN/ASep 21, 2026
CVE-2026-36470: n/a: CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.phpN/AN/AN/ASep 21, 2026
CVE-2026-36469: n/a: CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet…N/AN/AN/ASep 21, 2026
226-250 of 788572