The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-52740: gocd: GoCD is a continuous deliver serverN/A5.3 MediumN/ASep 21, 2026
CVE-2026-94404: MISP: MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser…N/A7.1 HighN/ASep 21, 2026
CVE-2026-94401: MISP: MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access…N/A8.3 HighN/ASep 21, 2026
CVE-2026-94394: MISP: When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall…N/A6.3 MediumN/ASep 21, 2026
CVE-2026-94393: MISP: When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without…N/A6.4 MediumN/ASep 21, 2026
CVE-2026-94387: aureuserp: Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where…5.4 Medium5.1 MediumN/ASep 21, 2026
CVE-2026-94382: henrygd beszel: Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE…4.2 Medium2.3 LowN/ASep 21, 2026
CVE-2026-93884: Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBERN/AN/AN/ASep 21, 2026
CVE-2026-88807: X.org libXrender: A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject…N/A8.9 HighN/ASep 21, 2026
CVE-2026-88806: x.org libX11: A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing…7.5 HighN/AN/ASep 21, 2026
CVE-2026-85220: Thinkst Applied Research Canary: A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a…3.7 LowN/AN/ASep 21, 2026
CVE-2025-71421: uvdesk: UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint…7.2 High8.6 HighN/ASep 21, 2026
CVE-2025-71420: uvdesk: UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that…4.3 Medium5.3 MediumN/ASep 21, 2026
CVE-2025-71419: uvdesk: UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer…5.4 Medium5.1 MediumN/ASep 21, 2026
CVE-2026-94383: MISP: The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file…N/A8.6 HighN/ASep 21, 2026
CVE-2026-94381: MISP: MISP has a security issue that can let a user gain more access than their API key is supposed to allowN/A8.7 HighN/ASep 21, 2026
CVE-2026-94379: MISP: The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several…N/A6.9 MediumN/ASep 21, 2026
CVE-2026-94374: MISP: MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event…N/A8.3 HighN/ASep 21, 2026
CVE-2026-94373: MISP: MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript componentN/A6.3 MediumN/ASep 21, 2026
CVE-2026-94372: MISP: MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index pageN/A6.3 MediumN/ASep 21, 2026
CVE-2026-94216: ST Engineering iDirect: A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 202607174.3 Medium2.1 LowN/ASep 21, 2026
CVE-2026-94214: ST Engineering iDirect: A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 202607174.3 Medium2.1 LowN/ASep 21, 2026
CVE-2026-94211: Hyve5 Leantime: A vulnerability has been found in Hyve5 Leantime up to 3.9.82.4 Low1.9 LowN/ASep 21, 2026
CVE-2026-84285: Dassault Systèmes Tuleap Enterprise Edition: An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an…8.8 HighN/AN/ASep 21, 2026
CVE-2026-94368: Red Hat Red Hat Openshift Data Foundation 4: A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object…7.1 HighN/AN/ASep 21, 2026
301-325 of 497849