The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-55071: SepineTam mcp-for-stata: MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design8.4 HighN/A0%Sep 21, 2026
CVE-2026-55060: gocd: GoCD is a continuous deliver server3.7 LowN/A0%Sep 21, 2026
CVE-2026-54584: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A5.3 Medium0%Sep 21, 2026
CVE-2026-52743: gocd: GoCD is a continuous deliver server4.3 MediumN/A0%Sep 21, 2026
CVE-2026-52742: gocd: GoCD is a continuous deliver serverN/A5.1 Medium0%Sep 21, 2026
CVE-2026-52741: gocd: GoCD is a continuous deliver serverN/A7.5 High0%Sep 21, 2026
CVE-2026-52740: gocd: GoCD is a continuous deliver serverN/A5.3 Medium0%Sep 21, 2026
CVE-2026-94404: MISP: MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser…N/A7.1 High0%Sep 21, 2026
CVE-2026-94401: MISP: MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access…N/A8.3 High0%Sep 21, 2026
CVE-2026-94394: MISP: When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall…N/A6.3 Medium0%Sep 21, 2026
CVE-2026-94393: MISP: When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without…N/A6.4 Medium0%Sep 21, 2026
CVE-2026-94387: aureuserp: Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where…5.4 Medium5.1 Medium0%Sep 21, 2026
CVE-2026-94382: henrygd beszel: Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE…4.2 Medium2.3 Low0%Sep 21, 2026
CVE-2026-93884: Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBERN/AN/AN/ASep 21, 2026
CVE-2026-88807: X.org libXrender: A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject…N/A8.9 High0%Sep 21, 2026
CVE-2026-88806: x.org libX11: A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing…7.5 HighN/A0%Sep 21, 2026
CVE-2026-85220: Thinkst Applied Research Canary: A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a…3.7 LowN/A0%Sep 21, 2026
CVE-2025-71421: uvdesk: UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint…7.2 High8.6 High0%Sep 21, 2026
CVE-2025-71420: uvdesk: UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that…4.3 Medium5.3 Medium0%Sep 21, 2026
CVE-2025-71419: uvdesk: UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer…5.4 Medium5.1 Medium0%Sep 21, 2026
CVE-2026-94383: MISP: The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file…N/A8.6 High0%Sep 21, 2026
CVE-2026-94381: MISP: MISP has a security issue that can let a user gain more access than their API key is supposed to allowN/A8.7 High0%Sep 21, 2026
CVE-2026-94379: MISP: The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several…N/A6.9 Medium0%Sep 21, 2026
CVE-2026-94374: MISP: MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event…N/A8.3 High0%Sep 21, 2026
CVE-2026-94373: MISP: MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript componentN/A6.3 Medium0%Sep 21, 2026
376-400 of 401359