The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-84099: Unknown wpstorecart: The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that…N/AN/A0%Sep 12, 2026
CVE-2026-84047: Unknown Album Cover Finder: The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it…N/AN/A0%Sep 12, 2026
CVE-2026-84025: Unknown BEAR: The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data…N/AN/A0%Sep 12, 2026
CVE-2026-84024: Unknown BEAR: The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration,…N/AN/A0%Sep 12, 2026
CVE-2026-84023: Unknown BEAR: The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy…N/AN/A0%Sep 12, 2026
CVE-2026-82851: Unknown Masteriyo LMS: The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a…N/AN/A0%Sep 12, 2026
CVE-2026-82847: Unknown Masteriyo LMS: The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting…N/AN/A0%Sep 12, 2026
CVE-2026-82845: Unknown Masteriyo LMS: The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being…N/AN/A0%Sep 12, 2026
CVE-2026-81742: Unknown BE REST Endpoints: The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets…N/AN/A0%Sep 12, 2026
CVE-2026-81429: Unknown Export & Import WPBakery Page Builder: The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its…N/AN/A0%Sep 12, 2026
CVE-2026-81402: Unknown DS Ad Rotator: The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type…N/AN/A0%Sep 12, 2026
CVE-2026-81090: Unknown Gpx2Graphics: The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate…N/AN/A0%Sep 12, 2026
CVE-2026-80494: Unknown Yogeta WP Cloud: The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a…N/AN/A0%Sep 12, 2026
CVE-2026-80491: Unknown SAMO Forms: The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL…N/AN/A0%Sep 12, 2026
CVE-2026-78152: Unknown SureRank SEO: The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the…N/AN/A0%Sep 12, 2026
CVE-2026-77753: Unknown Temporary Login Without Password: The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an…N/AN/A0%Sep 12, 2026
CVE-2026-77752: Unknown Temporary Login Without Password: The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary…N/AN/A0%Sep 12, 2026
CVE-2026-77705: Unknown Booking for Appointments and Events Calendar: The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a…N/AN/A0%Sep 12, 2026
CVE-2026-77689: Unknown Booking for Appointments and Events Calendar: The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was…N/AN/A0%Sep 12, 2026
CVE-2026-77006: Unknown WebTotem Backups: The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the…N/AN/A0%Sep 12, 2026
CVE-2026-77005: Unknown CODE MONKEYS PROPOSALS: The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a…N/AN/A0%Sep 12, 2026
CVE-2026-75800: Unknown Frontegg SAML SSO: The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication…N/AN/A0%Sep 12, 2026
CVE-2026-83532: Unknown Custom Menu Wizard Widget: The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes…N/AN/A0%Sep 12, 2026
CVE-2026-87719: GitLab: GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and…9.9 CriticalN/A1%Sep 12, 2026
CVE-2026-85706: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and…10.0 CriticalN/A1%Sep 12, 2026
76-100 of 556648