The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-94490: n/a OctoPrint: A security flaw has been discovered in OctoPrint 1.0.04.7 Medium2.0 Low2%Sep 22, 2026
CVE-2026-94489: n/a OctoPrint: A vulnerability was identified in OctoPrint 1.0.04.3 Medium2.1 Low0%Sep 22, 2026
CVE-2026-94426: xuxueli xxl-job: A vulnerability was determined in xuxueli xxl-job up to 3.5.03.5 Low2.0 Low0%Sep 21, 2026
CVE-2026-94425: Moore Threads MTT S80 Driver Package: A vulnerability was found in Moore Threads MTT S80 Driver Package 340.1508.8 High9.3 Critical0%Sep 21, 2026
CVE-2026-94627: vllm-project vllm: vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child…7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94626: vllm-project vllm: vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion…7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94625: vllm-project vllm: vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests…5.3 Medium6.9 Medium0%Sep 21, 2026
CVE-2026-94624: vllm-project vllm: vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is…7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94623: vllm-project vllm: vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation…7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94622: vllm-project vllm: vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for…7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94540: MrPear DesktopSMS: DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS,…7.7 High7.4 High0%Sep 21, 2026
CVE-2026-94536: dromara lamp-cloud: lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing…4.3 Medium5.3 Medium0%Sep 21, 2026
CVE-2026-94535: dromara lamp-cloud: lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows…7.1 High7.1 High0%Sep 21, 2026
CVE-2026-94534: dromara lamp-cloud: lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints,…7.1 High7.1 High0%Sep 21, 2026
CVE-2026-94533: dromara lamp-cloud: lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows…6.5 Medium7.1 High0%Sep 21, 2026
CVE-2026-94532: dromara lamp-cloud: lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows…6.5 Medium7.1 High0%Sep 21, 2026
CVE-2026-93340: Gladys Assistant: Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote…6.8 Medium7.4 High0%Sep 21, 2026
CVE-2026-88756: n/a: Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array…N/AN/A0%Sep 21, 2026
CVE-2026-88738: n/a: Jazzware RT1000 Edge webUI v8.8 HighN/A0%Sep 21, 2026
CVE-2026-79079: n/a: An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and…7.8 HighN/A0%Sep 21, 2026
CVE-2026-78847: n/a: An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to…9.8 CriticalN/A0%Sep 21, 2026
CVE-2026-78806: n/a: An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker…N/AN/A0%Sep 21, 2026
CVE-2026-65980: chartbrew: Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create…N/A7.9 High0%Sep 21, 2026
CVE-2026-61852: chartbrew: Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create…N/A5.8 Medium0%Sep 21, 2026
CVE-2026-61851: chartbrew: Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create…N/A6.5 Medium0%Sep 21, 2026
476-500 of 673429