The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-85751: Mailu: Mailu is a mail server distributed as a set of Docker images9.8 CriticalN/AN/ASep 21, 2026
CVE-2026-84298: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale3.1 LowN/AN/ASep 21, 2026
CVE-2026-82412: ntop ntopng: ntopng is a web-based network traffic monitoring application8.8 HighN/AN/ASep 21, 2026
CVE-2026-77166: Nextcloud Collectives: The emoji field in the page emoji update endpoint does not properly validate user input2.4 LowN/AN/ASep 21, 2026
CVE-2026-77165: Nextcloud Server: File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no…6.5 MediumN/AN/ASep 21, 2026
CVE-2026-63342: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale6.3 MediumN/AN/ASep 21, 2026
CVE-2026-61687: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale7.1 HighN/AN/ASep 21, 2026
CVE-2026-61681: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale4.1 MediumN/AN/ASep 21, 2026
CVE-2026-55563: feast-dev feast: Feast is the open source feature store for AI and machine learningN/A8.9 HighN/ASep 21, 2026
CVE-2026-53940: conda: Conda is a system-level binary package and environment manager that runs on major operating systems and platforms8.8 HighN/AN/ASep 21, 2026
CVE-2026-36472: n/a: CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS)5.2 MediumN/AN/ASep 21, 2026
CVE-2026-36471: n/a: Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote…N/AN/AN/ASep 21, 2026
CVE-2026-36470: n/a: CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.phpN/AN/AN/ASep 21, 2026
CVE-2026-36469: n/a: CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet…N/AN/AN/ASep 21, 2026
CVE-2026-36468: n/a: Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an…6.1 MediumN/AN/ASep 21, 2026
CVE-2026-36467: n/a: Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote…7.2 HighN/AN/ASep 21, 2026
CVE-2026-94301: Apache Software Foundation Apache MINA: The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via…9.8 CriticalN/AN/ASep 21, 2026
CVE-2026-94184: Red Hat: A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support8.1 HighN/AN/ASep 21, 2026
CVE-2026-93339: Metaphor Creations Ditty: Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that…5.4 Medium5.1 MediumN/ASep 21, 2026
CVE-2026-86473: Apache Software Foundation Apache Airflow: Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie9.1 CriticalN/AN/ASep 21, 2026
CVE-2026-82355: Apache Software Foundation Apache Airflow: When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token,…4.2 MediumN/AN/ASep 21, 2026
CVE-2026-80110: Red Hat: A flaw was found in pki-core8.1 HighN/AN/ASep 21, 2026
CVE-2026-75939: Red Hat Red Hat OpenShift Container Platform 4: A flaw was found in openshift/oc-mirror7.4 HighN/AN/ASep 21, 2026
CVE-2026-75158: Apache Software Foundation Apache Airflow: Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting…4.3 MediumN/AN/ASep 21, 2026
CVE-2026-71543: openbao: OpenBao is an open source identity-based secrets management systemN/A7.5 HighN/ASep 21, 2026
251-275 of 788572