The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-61681: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale4.1 MediumN/A0%Sep 21, 2026
CVE-2026-55563: feast-dev feast: Feast is the open source feature store for AI and machine learningN/A8.9 High0%Sep 21, 2026
CVE-2026-53940: conda: Conda is a system-level binary package and environment manager that runs on major operating systems and platforms8.8 HighN/A0%Sep 21, 2026
CVE-2026-36472: n/a: CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS)5.2 MediumN/A0%Sep 21, 2026
CVE-2026-36471: n/a: Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote…N/AN/A0%Sep 21, 2026
CVE-2026-36469: n/a: CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet…N/AN/A0%Sep 21, 2026
CVE-2026-36468: n/a: Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an…6.1 MediumN/A0%Sep 21, 2026
CVE-2026-36467: n/a: Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote…7.2 HighN/A1%Sep 21, 2026
CVE-2026-94301: Apache Software Foundation Apache MINA: The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via…9.8 CriticalN/A0%Sep 21, 2026
CVE-2026-94184: Red Hat: A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support8.1 HighN/A1%Sep 21, 2026
CVE-2026-93339: Metaphor Creations Ditty: Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that…5.4 Medium5.1 Medium0%Sep 21, 2026
CVE-2026-86473: Apache Software Foundation Apache Airflow: Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie9.1 CriticalN/A0%Sep 21, 2026
CVE-2026-82355: Apache Software Foundation Apache Airflow: When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token,…4.2 MediumN/A0%Sep 21, 2026
CVE-2026-80110: Red Hat: A flaw was found in pki-core8.1 HighN/A0%Sep 21, 2026
CVE-2026-75939: Red Hat Red Hat OpenShift Container Platform 4: A flaw was found in openshift/oc-mirror7.4 HighN/A0%Sep 21, 2026
CVE-2026-75158: Apache Software Foundation Apache Airflow: Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting…4.3 MediumN/A0%Sep 21, 2026
CVE-2026-71543: openbao: OpenBao is an open source identity-based secrets management systemN/A7.5 High0%Sep 21, 2026
CVE-2026-68919: gocd: GoCD is a continuous deliver serverN/A7.0 High0%Sep 21, 2026
CVE-2026-61630: lucasdillmann nginx-ignition: nginx ignition is a user interface for the nginx web server4.2 MediumN/A0%Sep 21, 2026
CVE-2026-61629: lucasdillmann nginx-ignition: nginx ignition is a user interface for the nginx web server7.5 HighN/A0%Sep 21, 2026
CVE-2026-61628: lucasdillmann nginx-ignition: nginx ignition is a user interface for the nginx web server8.1 HighN/A0%Sep 21, 2026
CVE-2026-55870: gocd: GoCD is a continuous deliver serverN/A2.3 Low0%Sep 21, 2026
CVE-2026-55625: gocd: GoCD is a continuous deliver server4.9 MediumN/A0%Sep 21, 2026
CVE-2026-55567: bleachbit: BleachBit cleans files to free disk space and to maintain privacy7.8 HighN/A0%Sep 21, 2026
CVE-2026-55074: chofstede ansible_jailexec: Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexecN/A8.2 High0%Sep 21, 2026
351-375 of 507429