The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-86707: The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is…N/AN/AN/ASep 17, 2026
CVE-2026-86446: The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is…N/AN/AN/ASep 17, 2026
CVE-2026-85130: The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for…N/AN/AN/ASep 17, 2026
CVE-2026-85128: The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration…N/AN/AN/ASep 17, 2026
CVE-2025-15697: The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of…N/AN/AN/ASep 17, 2026
CVE-2026-87935: Unrestricted Upload of File with Dangerous Type8.1 HighN/AN/ASep 17, 2026
CVE-2026-87796: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-50604: Acer Acer Agent Service: A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSenseN/A4.9 MediumN/ASep 17, 2026
CVE-2026-25294: Qualcomm, Inc. Snapdragon: Transient DOS while parsing frame during channel usage.7.4 HighN/AN/ASep 17, 2026
CVE-2026-25290: Qualcomm, Inc. Snapdragon: Memory Corruption when validating large data buffers from external sources using addition to check buffer length.7.8 HighN/AN/ASep 17, 2026
CVE-2026-25284: Qualcomm, Inc. Snapdragon: Information Disclosure when a pointer is reused after being deallocated.7.3 HighN/AN/ASep 17, 2026
CVE-2026-25283: Qualcomm, Inc. Snapdragon: Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.8.8 HighN/AN/ASep 17, 2026
CVE-2026-25282: Qualcomm, Inc. Snapdragon: Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.7.9 HighN/AN/ASep 17, 2026
CVE-2026-25281: Qualcomm, Inc. Snapdragon: Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.7.4 HighN/AN/ASep 17, 2026
CVE-2026-25280: Qualcomm, Inc. Snapdragon: Memory corruption when processing escape handling flow with insufficient user buffer sizes.7.8 HighN/AN/ASep 17, 2026
CVE-2026-25278: Qualcomm, Inc. Snapdragon: Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data…7.8 HighN/AN/ASep 17, 2026
CVE-2026-25275: Qualcomm, Inc. Snapdragon: Transient DOS when processing authentication frames with invalid FILS information element header lengths.7.5 HighN/AN/ASep 17, 2026
CVE-2026-25261: Qualcomm, Inc. Snapdragon: Memory corruption while processing rear sensor IOCTL calls.6.7 MediumN/AN/ASep 17, 2026
CVE-2026-24081: Qualcomm, Inc. Snapdragon: Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully…7.4 HighN/AN/ASep 17, 2026
CVE-2026-24075: Qualcomm, Inc. Snapdragon: Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper…7.8 HighN/AN/ASep 17, 2026
CVE-2026-24074: Qualcomm, Inc. Snapdragon: Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy…7.8 HighN/AN/ASep 17, 2026
CVE-2026-24073: Qualcomm, Inc. Snapdragon: Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.7.8 HighN/AN/ASep 17, 2026
CVE-2025-59607: Qualcomm, Inc. Snapdragon: Memory Corruption when copying large input data exceeds normal allocation limits.7.8 HighN/AN/ASep 17, 2026
CVE-2026-92839: Canva Desktop before v1.125.0 performed double decoding in the deeplink handler4.3 MediumN/AN/ASep 17, 2026
CVE-2026-86311: Cross-site Scripting (XSS)6.4 MediumN/AN/ASep 17, 2026
26-50 of 399180