The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-94532: dromara lamp-cloud: lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows…6.5 Medium7.1 High0%Sep 21, 2026
CVE-2026-93340: Gladys Assistant: Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote…6.8 Medium7.4 High0%Sep 21, 2026
CVE-2026-88756: n/a: Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array…N/AN/A0%Sep 21, 2026
CVE-2026-88738: n/a: Jazzware RT1000 Edge webUI v8.8 HighN/A0%Sep 21, 2026
CVE-2026-79079: n/a: An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and…7.8 HighN/A0%Sep 21, 2026
CVE-2026-78847: n/a: An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to…9.8 CriticalN/A0%Sep 21, 2026
CVE-2026-78806: n/a: An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker…N/AN/A0%Sep 21, 2026
CVE-2026-65980: chartbrew: Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create…N/A7.9 High0%Sep 21, 2026
CVE-2026-61852: chartbrew: Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create…N/A5.8 Medium0%Sep 21, 2026
CVE-2026-61851: chartbrew: Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create…N/A6.5 Medium0%Sep 21, 2026
CVE-2026-61743: chartbrew: Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create…6.3 MediumN/A0%Sep 21, 2026
CVE-2026-61541: kap-sh zapros: Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests…N/A6.9 Medium0%Sep 21, 2026
CVE-2026-59830: discourse: Discourse is an open-source discussion platform5.4 MediumN/A0%Sep 21, 2026
CVE-2026-59815: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks4.3 MediumN/A0%Sep 21, 2026
CVE-2026-59814: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks7.6 HighN/A0%Sep 21, 2026
CVE-2026-55210: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks7.4 HighN/A0%Sep 21, 2026
CVE-2026-46650: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks4.4 MediumN/A0%Sep 21, 2026
CVE-2026-17054: zephyrproject zephyr: The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP…5.3 MediumN/A0%Sep 21, 2026
CVE-2026-15890: zephyrproject zephyr: The default AEAD nonce provider for the PSA Internal Trusted Storage transform module,…5.3 MediumN/A0%Sep 21, 2026
CVE-2026-94588: Proxmox pmg-api: In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality4.4 MediumN/A0%Sep 21, 2026
CVE-2026-94572: OpenStack Octavia: In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers…N/A9.4 Critical0%Sep 21, 2026
CVE-2026-94571: OpenStack Octavia: In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy…N/A9.4 Critical0%Sep 21, 2026
CVE-2026-94424: Moore Threads MTT S80 Driver Package: A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.1508.8 High9.3 Critical0%Sep 21, 2026
CVE-2026-93433: Red Hat: A flaw was found in libstoragemgmt5.5 MediumN/A0%Sep 21, 2026
CVE-2026-88746: n/a: idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.7.1 HighN/A0%Sep 21, 2026
726-750 of 397415