The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
TitleEitWModules
CVE-2026-77063: multer: multer is a middleware for handling multipart/form-data in Node.js3.7 LowN/AN/AAug 28, 2026
CVE-2026-77037: multer: multer is a middleware for handling multipart/form-data in Node.js7.5 HighN/AN/AAug 28, 2026
CVE-2026-76651: TP-Link System Inc. TL-WR841N v14: A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing…N/A5.3 MediumN/AAug 28, 2026
CVE-2026-76650: TP-Link System Inc. TL-WR841N v14: A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state…N/A5.3 MediumN/AAug 28, 2026
CVE-2026-76649: TP-Link System Inc. TL-WR841N v14: A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action…N/A5.3 MediumN/AAug 28, 2026
CVE-2026-75118: TP-Link Systems Inc. TL-MR100 v3.20: A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100…N/A8.7 HighN/AAug 28, 2026
CVE-2026-55891: PrivateBin: PrivateBin is an online pastebin where the server has zero knowledge of pasted data0.0 NoneN/AN/AAug 28, 2026
CVE-2026-55763: klever-io klever-go: Klever-Go is the Go implementation of the Klever blockchain protocolN/A8.7 HighN/AAug 28, 2026
CVE-2026-55696: PrivateBin: PrivateBin is an online pastebin where the server has zero knowledge of pasted data4.3 MediumN/AN/AAug 28, 2026
CVE-2026-55678: Basekick-Labs arc: Arc is an open, SQL-native time-series database for telemetryN/A6.9 MediumN/AAug 28, 2026
CVE-2026-51665: n/a: Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated…N/AN/AN/AAug 28, 2026
CVE-2026-51664: n/a: Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated…N/AN/AN/AAug 28, 2026
CVE-2026-51663: n/a: Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated…N/AN/AN/AAug 28, 2026
CVE-2026-51662: n/a: Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…N/AN/AN/AAug 28, 2026
CVE-2026-51661: n/a: Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…N/AN/AN/AAug 28, 2026
CVE-2026-3686: IBM Cloud Pak for Data System: IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper…6.2 MediumN/AN/AAug 28, 2026
CVE-2026-3627: IBM Concert: IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection9.1 CriticalN/AN/AAug 28, 2026
CVE-2026-22056: NetApp StorageGRID: StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are…N/A2.3 LowN/AAug 28, 2026
CVE-2026-19295: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands…9.9 CriticalN/AN/AAug 28, 2026
CVE-2026-19294: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's…6.4 MediumN/AN/AAug 28, 2026
CVE-2026-19286: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper…9.8 CriticalN/AN/AAug 28, 2026
CVE-2026-18904: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject…8.2 HighN/AN/AAug 28, 2026
CVE-2026-18899: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.7.5 HighN/AN/AAug 28, 2026
CVE-2026-18891: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive…8.2 HighN/AN/AAug 28, 2026
CVE-2026-18729: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to…8.8 HighN/AN/AAug 28, 2026
26-50 of 385708