The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92593: craftcms cms: Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the…8.8 High8.7 HighN/ASep 16, 2026
CVE-2026-92592: craftcms cms: Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun…8.8 High8.7 HighN/ASep 16, 2026
CVE-2026-92591: craftcms cms: Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which…5.9 Medium8.2 HighN/ASep 16, 2026
CVE-2026-92590: craftcms cms: Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated…5.4 Medium5.1 MediumN/ASep 16, 2026
CVE-2026-92589: craftcms cms: Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder…4.3 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92588: n8n-io n8n: n8n is a workflow automation platform4.4 Medium5.9 MediumN/ASep 16, 2026
CVE-2026-92587: n8n-io n8n: n8n is a workflow automation platform5.0 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92586: WWBN AVideo: AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the…4.3 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92585: WWBN AVideo: AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the…4.3 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92584: WWBN AVideo: AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability6.1 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92583: WWBN AVideo: AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment…6.5 Medium6.9 MediumN/ASep 16, 2026
CVE-2026-92582: WWBN AVideo: AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery7.1 High7.1 HighN/ASep 16, 2026
CVE-2026-92581: WWBN AVideo: In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation,…4.3 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92580: WWBN AVideo: In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection8.8 High8.7 HighN/ASep 16, 2026
CVE-2026-92579: WWBN AVideo: In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without…5.4 Medium5.3 MediumN/ASep 16, 2026
CVE-2026-92578: WWBN AVideo: WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as…8.1 High9.2 CriticalN/ASep 16, 2026
CVE-2026-92577: WWBN AVideo: In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the…7.5 High8.7 HighN/ASep 16, 2026
CVE-2026-92576: HKUDS nanobot: HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the…8.6 High9.2 CriticalN/ASep 16, 2026
CVE-2026-89034: Missing Authentication for Critical Function6.5 Medium7.1 HighN/ASep 16, 2026
CVE-2026-85469: Red Hat Red Hat Quay 3: A flaw was found in quay-builder-qemu8.0 HighN/AN/ASep 16, 2026
CVE-2026-64684: modelcontextprotocol rust-sdk: RMCP is an official Rust SDK for the Model Context Protocol6.8 MediumN/AN/ASep 16, 2026
CVE-2026-61597: Cross-site Scripting (XSS)N/A5.1 MediumN/ASep 16, 2026
CVE-2026-61594: Missing Authentication for Critical Function9.1 CriticalN/AN/ASep 16, 2026
CVE-2026-61592: Session Fixation7.4 HighN/AN/ASep 16, 2026
CVE-2026-61591: Insufficient Verification of Data Authenticity8.1 HighN/AN/ASep 16, 2026
76-100 of 401009