The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
TitleEitWModules
CVE-2026-10522: Unknown MemberHero: The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend…N/AN/AN/AAug 29, 2026
CVE-2026-41012: Cloud Foundry bosh-vsphere-cpi-release: Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and…7.7 HighN/AN/AAug 29, 2026
CVE-2026-55867: Graylog2 graylog2-server: Graylog is a free and open log management platformN/A5.3 MediumN/AAug 28, 2026
CVE-2026-55860: mariadb-corporation, org.mariadb: MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java5.9 MediumN/AN/AAug 28, 2026
CVE-2026-55859: mariadb-corporation, org.mariadb: MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java5.9 MediumN/AN/AAug 28, 2026
CVE-2026-55858: mariadb-corporation mariadb-connector-j: MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases5.9 MediumN/AN/AAug 28, 2026
CVE-2026-55857: mariadb-corporation mariadb-connector-j: MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases5.9 MediumN/AN/AAug 28, 2026
CVE-2026-55856: mariadb-corporation mariadb-connector-j: MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases5.9 MediumN/AN/AAug 28, 2026
CVE-2026-55855: mariadb-corporation mariadb-connector-nodejs: MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases6.5 MediumN/AN/AAug 28, 2026
CVE-2026-55854: mariadb-corporation mariadb-connector-nodejs: MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases5.9 MediumN/AN/AAug 28, 2026
CVE-2026-55848: mapfish: mapfish-print is a component of MapFish for printing templated cartographic maps8.6 HighN/AN/AAug 28, 2026
CVE-2026-55841: Graylog2 graylog2-server: Graylog is a free and open log management platform7.5 HighN/AN/AAug 28, 2026
CVE-2026-55785: free5gc: free5GC is an open-source implementation of the 5G core network3.7 LowN/AN/AAug 28, 2026
CVE-2026-55784: free5gc: free5GC is an open-source implementation of the 5G core network7.5 HighN/AN/AAug 28, 2026
CVE-2026-55779: silverstripe silverstripe-versioned: Silverstripe Versioned provides versioning for Silverstripe models5.4 MediumN/AN/AAug 28, 2026
CVE-2026-55764: klever-io klever-go: Klever-Go is the Go implementation of the Klever blockchain protocolN/A8.7 HighN/AAug 28, 2026
CVE-2026-82333: multer: multer is a middleware for handling multipart/form-data in Node.js7.5 HighN/AN/AAug 28, 2026
CVE-2026-82018: IGEL: IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the…6.1 Medium6.8 MediumN/AAug 28, 2026
CVE-2026-82017: IGEL: IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that…7.6 High8.6 HighN/AAug 28, 2026
CVE-2026-81533: MongoDB BI Connector ODBC Driver: An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL…7.1 High6.0 MediumN/AAug 28, 2026
CVE-2026-81532: MongoDB BI Connector ODBC Driver: A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a…8.8 High8.7 HighN/AAug 28, 2026
CVE-2026-81520: MongoDB BI Connector: A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session…7.5 High8.7 HighN/AAug 28, 2026
CVE-2026-81518: MongoDB BI Connector: When mongosqld is configured with a client certificate authority file, the listener requests a client certificate…7.5 High8.7 HighN/AAug 28, 2026
CVE-2026-81517: MongoDB BI Connector: An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough…7.5 High8.7 HighN/AAug 28, 2026
CVE-2026-81490: MongoDB BI Connector: A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the…7.7 High8.3 HighN/AAug 28, 2026
26-50 of 384709