The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
TitleEitWModules
CVE-2026-81200: Unknown MasterStudy LMS WordPress Plugin: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order…2.7 LowN/A0%Aug 29, 2026
CVE-2026-81026: Unknown MasterStudy LMS WordPress Plugin: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or…4.8 MediumN/A0%Aug 29, 2026
CVE-2026-80488: Unknown WP Ultimate CSV Importer: The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values…4.1 MediumN/A0%Aug 29, 2026
CVE-2026-80311: Unknown Stripe Payment Forms by WP Full Pay: The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to…4.3 MediumN/A0%Aug 29, 2026
CVE-2026-77786: Unknown Rank Math SEO: The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds…4.9 MediumN/A0%Aug 29, 2026
CVE-2026-77704: Unknown Booking for Appointments and Events Calendar: The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the…2.7 LowN/A0%Aug 29, 2026
CVE-2026-77012: Unknown 爱采集数据采集和发布插件: The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated…9.3 CriticalN/A0%Aug 29, 2026
CVE-2026-77010: Unknown HEL Online Classroom: AI-powered Online Classrooms: The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation…6.5 MediumN/A0%Aug 29, 2026
CVE-2026-77008: Unknown HEL Online Classroom: AI-powered Online Classrooms: The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation…6.5 MediumN/A0%Aug 29, 2026
CVE-2026-77007: Unknown HEL Online Classroom: AI-powered Online Classrooms: The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any…7.5 HighN/A0%Aug 29, 2026
CVE-2026-76586: Unknown Appointment Booking Calendar Plugin and Scheduling Plugin: The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount…7.5 HighN/A0%Aug 29, 2026
CVE-2026-76548: Unknown User Profile Builder: The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature,…8.2 HighN/A0%Aug 29, 2026
CVE-2026-76547: Unknown User Profile Builder: The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when…6.6 MediumN/A0%Aug 29, 2026
CVE-2026-76546: Unknown User Profile Builder: The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes,…6.8 MediumN/A0%Aug 29, 2026
CVE-2026-19430: Unknown Catfolders Document Gallery Pro: The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and…5.3 MediumN/A0%Aug 29, 2026
CVE-2026-18234: Unknown MStore API: The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling…6.5 MediumN/A0%Aug 29, 2026
CVE-2026-18233: Unknown MStore API: The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints…6.5 MediumN/A0%Aug 29, 2026
CVE-2026-17522: Unknown Newsletters: The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its…5.4 MediumN/A0%Aug 29, 2026
CVE-2026-17520: Unknown Newsletters: The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving…4.8 MediumN/A0%Aug 29, 2026
CVE-2026-16947: Unknown Total processing card payments for WooCommerce: The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path…9.1 CriticalN/A0%Aug 29, 2026
CVE-2026-16600: Unknown SmartAIPress: The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does…7.7 HighN/A0%Aug 29, 2026
CVE-2026-16259: Unknown Uix UserCenter: The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an…9.8 CriticalN/A0%Aug 29, 2026
CVE-2026-16061: Unknown Rest Routes: The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its…8.6 HighN/A0%Aug 29, 2026
CVE-2026-10522: Unknown MemberHero: The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend…N/AN/A0%Aug 29, 2026
CVE-2026-41012: Cloud Foundry bosh-vsphere-cpi-release: Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and…7.7 HighN/A0%Aug 29, 2026
326-350 of 386442