The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-79799: Hewlett Packard Enterprise (HPE) ClearPass Policy Manager (CPPM): A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote…8.8 HighN/AN/AOct 6, 2026
CVE-2026-76752: Hewlett Packard Enterprise (HPE) ClearPass Policy Manager (CPPM): Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass…9.8 CriticalN/AN/AOct 6, 2026
CVE-2026-76748: Hewlett Packard Enterprise (HPE) AOS-Switch (AOS-S): A privilege escalation vulnerability exists in the API of AOS-S8.8 HighN/AN/AOct 6, 2026
CVE-2026-104636: Gitea: Gitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request…N/AN/AN/AOct 6, 2026
CVE-2026-103007: Elastic Elasticsearch: Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative…7.2 HighN/AN/AOct 6, 2026
CVE-2026-102412: Elastic Kibana: Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality…6.5 MediumN/AN/AOct 6, 2026
CVE-2026-102406: Elastic Kibana: Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception8.8 HighN/AN/AOct 6, 2026
CVE-2026-102161: Arista Networks CloudVision CUE: An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load…8.8 High8.7 HighN/AOct 6, 2026
CVE-2026-101158: Arista Networks CloudVision Portal: A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload…8.4 High9.3 CriticalN/AOct 6, 2026
CVE-2026-101156: Arista Networks CloudVision CUE: A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store…8.4 High6.2 MediumN/AOct 6, 2026
CVE-2025-71384: n/a: Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi network) to execute OS commands by leveraging…6.7 MediumN/AN/AOct 6, 2026
CVE-2026-67270: Dell Container Storage Modules (CSM): Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation…8.2 HighN/AN/AOct 6, 2026
CVE-2026-63688: Dell Dell Container Storage Modules (CSM): Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical…10.0 CriticalN/AN/AOct 6, 2026
CVE-2026-104069: danielbrendel hortusfox-web: HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP…7.2 High8.6 HighN/AOct 6, 2026
CVE-2026-105919: Kusalkasilva Learning-Management-System: A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d27.3 High5.5 MediumN/AOct 6, 2026
CVE-2026-94293: Murrelektronik Software AAS Edge Client all versions: An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read…9.8 Critical9.3 Critical0%Oct 6, 2026
CVE-2026-94278: Unknown File Media Renamer: The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a…5.5 MediumN/A0%Oct 6, 2026
CVE-2026-59358: Cloud Foundry: Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated…N/A7.6 High0%Oct 6, 2026
CVE-2026-59357: Cloud Foundry: Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA…N/A6.5 Medium0%Oct 6, 2026
CVE-2026-103546: MongoDB, Inc. Mongodb Controllers for Kubernetes: In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who…4.3 Medium2.3 Low0%Oct 5, 2026
CVE-2026-77226: Camunda Camunda 7: Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's…8.1 High9.2 Critical1%Oct 5, 2026
CVE-2026-105447: Red Hat Red Hat Quay 3: A flaw was found in Quay5.5 MediumN/A0%Oct 5, 2026
CVE-2026-95263: Undefined Security Weakness7.2 HighN/A0%Oct 5, 2026
CVE-2026-105692: Improper Access Control5.4 MediumN/A0%Oct 5, 2026
CVE-2026-105689: Server-Side Request Forgery (SSRF)N/A6.0 Medium0%Oct 5, 2026
26-50 of 17415