The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-59830: discourse: Discourse is an open-source discussion platform5.4 MediumN/AN/ASep 21, 2026
CVE-2026-59815: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks4.3 MediumN/AN/ASep 21, 2026
CVE-2026-59814: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks7.6 HighN/AN/ASep 21, 2026
CVE-2026-55210: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks7.4 HighN/AN/ASep 21, 2026
CVE-2026-46650: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks4.4 MediumN/AN/ASep 21, 2026
CVE-2026-17054: zephyrproject zephyr: The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP…5.3 MediumN/AN/ASep 21, 2026
CVE-2026-15890: zephyrproject zephyr: The default AEAD nonce provider for the PSA Internal Trusted Storage transform module,…5.3 MediumN/AN/ASep 21, 2026
CVE-2026-94588: Proxmox pmg-api: In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality4.4 MediumN/AN/ASep 21, 2026
CVE-2026-94572: OpenStack Octavia: In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers…N/A9.4 CriticalN/ASep 21, 2026
CVE-2026-94571: OpenStack Octavia: In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy…N/A9.4 CriticalN/ASep 21, 2026
CVE-2026-94424: Moore Threads MTT S80 Driver Package: A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.1508.8 High9.3 CriticalN/ASep 21, 2026
CVE-2026-93433: Red Hat: A flaw was found in libstoragemgmt5.5 MediumN/AN/ASep 21, 2026
CVE-2026-88746: n/a: idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.N/AN/AN/ASep 21, 2026
CVE-2026-88745: n/a: EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.N/AN/AN/ASep 21, 2026
CVE-2026-88467: n/a: CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of…N/AN/AN/ASep 21, 2026
CVE-2026-88412: n/a: An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1…5.3 MediumN/AN/ASep 21, 2026
CVE-2026-88411: n/a: Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1…7.5 HighN/AN/ASep 21, 2026
CVE-2026-88410: n/a: The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected…7.1 HighN/AN/ASep 21, 2026
CVE-2026-88409: n/a: FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix…8.8 HighN/AN/ASep 21, 2026
CVE-2026-88408: n/a: FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function…6.5 MediumN/AN/ASep 21, 2026
CVE-2026-88407: n/a: An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to…7.5 HighN/AN/ASep 21, 2026
CVE-2026-88406: n/a: FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses…7.5 HighN/AN/ASep 21, 2026
CVE-2026-88405: n/a: A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function…N/AN/AN/ASep 21, 2026
CVE-2026-88404: n/a: A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function…N/AN/AN/ASep 21, 2026
CVE-2026-88403: n/a: A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers…N/AN/AN/ASep 21, 2026
76-100 of 691462