The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92235: roxnor WP Ultimate Review: The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,…8.1 HighN/A0%Sep 22, 2026
CVE-2026-91092: tomdever wpForo Forum: The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.54.3 MediumN/A0%Sep 22, 2026
CVE-2026-87082: Loop with Unreachable Exit Condition ('Infinite Loop')7.5 HighN/A0%Sep 22, 2026
CVE-2026-87081: Inefficient Algorithmic Complexity7.5 HighN/A0%Sep 22, 2026
CVE-2026-87080: Improper Validation of Syntactic Correctness of Input9.1 CriticalN/A0%Sep 22, 2026
CVE-2026-87079: Inefficient Algorithmic Complexity7.5 HighN/A0%Sep 22, 2026
CVE-2026-87078: Missing Release of Memory after Effective Lifetime9.1 CriticalN/A0%Sep 22, 2026
CVE-2026-7622: codexpert: The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.14.3 MediumN/A0%Sep 22, 2026
CVE-2026-74766: Use After Free8.4 HighN/A0%Sep 22, 2026
CVE-2026-74765: Integer Overflow or Wraparound6.5 MediumN/A0%Sep 22, 2026
CVE-2026-6922: wptb WP Table Builder – Drag & Drop Table Builder: The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all…7.1 HighN/A0%Sep 22, 2026
CVE-2026-4123: rwelephant01 RW Elephant Rental Inventory: The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and…4.3 MediumN/A0%Sep 22, 2026
CVE-2026-1645: prasunsen Hostel: The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and…4.4 MediumN/A0%Sep 22, 2026
CVE-2026-18439: themeum Tutor LMS – eLearning and online course solution: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object…4.3 MediumN/A0%Sep 22, 2026
CVE-2026-18345: wpusermanager WP User Manager – User Profile Builder & Membership: The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability…4.3 MediumN/A0%Sep 22, 2026
CVE-2026-16778: livecomposer Live Composer – Free WordPress Website Builder: The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting…6.4 MediumN/A0%Sep 22, 2026
CVE-2026-12995: hiroaki-miyashita Custom Field Template: The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,…4.3 MediumN/A0%Sep 22, 2026
CVE-2025-1281: SeaTheme BM Content Builder: The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…8.8 HighN/A1%Sep 22, 2026
CVE-2025-1280: SeaTheme BM Content Builder: The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1…6.5 MediumN/A1%Sep 22, 2026
CVE-2025-14487: kamleshyadav Handily: The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing…5.3 MediumN/A0%Sep 22, 2026
CVE-2025-14486: kamleshyadav PixelPlay: The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks…5.3 MediumN/A0%Sep 22, 2026
CVE-2025-14484: kamleshyadav Image Buzz: The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization…5.3 MediumN/A0%Sep 22, 2026
CVE-2016-15059: Heap-based Buffer Overflow9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-94504: kstover: Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy…7.2 HighN/A0%Sep 22, 2026
CVE-2026-92438: Unknown Ninja Forms: The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the…8.8 HighN/A0%Sep 22, 2026
426-450 of 673429