The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2025-14487: kamleshyadav Handily: The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing…5.3 MediumN/A0%Sep 22, 2026
CVE-2025-14486: kamleshyadav PixelPlay: The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks…5.3 MediumN/A0%Sep 22, 2026
CVE-2025-14484: kamleshyadav Image Buzz: The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization…5.3 MediumN/A0%Sep 22, 2026
CVE-2016-15059: Heap-based Buffer Overflow9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-94504: kstover: Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy…7.2 HighN/A0%Sep 22, 2026
CVE-2026-92438: Unknown Ninja Forms: The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the…8.8 HighN/A0%Sep 22, 2026
CVE-2026-91827: Unknown Ninja Forms: The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when…7.5 HighN/A0%Sep 22, 2026
CVE-2026-89412: cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored…7.2 HighN/A0%Sep 22, 2026
CVE-2026-93655: wpdevelop Booking Calendar: The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill'…6.1 MediumN/A0%Sep 22, 2026
CVE-2026-88788: Unknown Text Styler: The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before…6.8 MediumN/A0%Sep 22, 2026
CVE-2026-85653: ajay Contextual Related Posts: The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes'…6.4 MediumN/A0%Sep 22, 2026
CVE-2026-12470: niteo CMP – Coming Soon & Maintenance Plugin by NiteoThemes: The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized…7.2 HighN/A0%Sep 22, 2026
CVE-2026-19658: LiquidWeb Give Tributes: The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,…9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-13355: Meta Box Meta Box Frontend Submission: The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and…9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-94493: Gigatech PDV5701: A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_11264010.0 Critical9.3 Critical1%Sep 22, 2026
CVE-2026-94492: Yonyou U8cloud: A security vulnerability has been detected in Yonyou U8cloud 5.x6.3 Medium2.1 Low0%Sep 22, 2026
CVE-2026-94491: Yonyou KSOA: A weakness has been identified in Yonyou KSOA 9.07.3 High5.5 Medium0%Sep 22, 2026
CVE-2026-93712: Path Traversal7.5 HighN/A0%Sep 22, 2026
CVE-2026-93711: HTTP Response Splitting6.5 MediumN/A0%Sep 22, 2026
CVE-2026-93710: Improper Cleanup on Thrown Exception7.5 HighN/A0%Sep 22, 2026
CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the…N/AN/A0%Sep 22, 2026
CVE-2026-76974: SAP_SE SAP Fiori Launchpad: SAP Fiori Launchpad does not sufficiently validate certain user-controlled input5.3 MediumN/A0%Sep 22, 2026
CVE-2026-94490: n/a OctoPrint: A security flaw has been discovered in OctoPrint 1.0.04.7 Medium2.0 Low2%Sep 22, 2026
CVE-2026-94489: n/a OctoPrint: A vulnerability was identified in OctoPrint 1.0.04.3 Medium2.1 Low0%Sep 22, 2026
CVE-2026-94426: xuxueli xxl-job: A vulnerability was determined in xuxueli xxl-job up to 3.5.03.5 Low2.0 Low0%Sep 21, 2026
451-475 of 673429