The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-84960: cbutlerjr WP-Members Membership Plugin: The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query…6.1 MediumN/AN/ASep 11, 2026
CVE-2026-81825: specialk: The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting…7.2 HighN/AN/ASep 11, 2026
CVE-2026-81754: fernandot: The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to…7.2 HighN/AN/ASep 11, 2026
CVE-2026-7438: boldthemes Bold Timeline Lite: The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and…6.4 MediumN/AN/ASep 11, 2026
CVE-2026-78172: themifyme Themify – WooCommerce Product Filter: The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query…6.1 MediumN/AN/ASep 11, 2026
CVE-2026-77150: unitecms Unlimited Elements For Elementor: The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via…6.1 MediumN/AN/ASep 11, 2026
CVE-2026-19991: stiofansisland: The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via…8.1 HighN/AN/ASep 11, 2026
CVE-2026-19985: comesio Relevanssi – A Better Search: The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up…6.1 MediumN/AN/ASep 11, 2026
CVE-2026-18964: premio: The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty…6.1 MediumN/AN/ASep 11, 2026
CVE-2026-18579: opajaap WP Photo Album Plus: The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…7.2 HighN/AN/ASep 11, 2026
CVE-2026-18562: realmag777 HUSKY – Products Filter for WooCommerce Professional: The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site…6.1 MediumN/AN/ASep 11, 2026
CVE-2026-18561: unitecms Unlimited Elements For Elementor: The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter…7.5 HighN/AN/ASep 11, 2026
CVE-2026-15462: gingerplugins: The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array…7.5 HighN/AN/ASep 11, 2026
CVE-2026-12215: xootix OTP Login & Register Woocommerce: The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in…5.3 MediumN/AN/ASep 11, 2026
CVE-2026-11496: edgarrojas: The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to…6.5 MediumN/AN/ASep 11, 2026
CVE-2026-11446: arraytics Booktics – Appointment Booking Calendar for Service Businesses: The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to…5.3 MediumN/AN/ASep 11, 2026
CVE-2026-89151: Forgejo: Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.3.5 LowN/AN/ASep 11, 2026
CVE-2026-88260: Brainzcompany Zenius EMS 8.0: Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input…N/A8.7 HighN/ASep 11, 2026
CVE-2026-78135: strongSwan: libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine5.6 MediumN/AN/ASep 11, 2026
CVE-2026-89145: flextype: Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error…4.2 Medium2.4 LowN/ASep 11, 2026
CVE-2026-89092: The GNU C Library glibc: The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server…4.2 MediumN/AN/ASep 11, 2026
CVE-2026-88914: Red Hat: A flaw was found in GStreamer's gst-plugins-good isomp4 plugin4.4 MediumN/AN/ASep 11, 2026
CVE-2026-78134: strongSwan: strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a…7.1 HighN/AN/ASep 11, 2026
CVE-2026-78133: strongSwan: libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.7.5 HighN/AN/ASep 11, 2026
CVE-2026-78132: strongSwan: strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for…7.5 HighN/AN/ASep 11, 2026
51-75 of 904430