The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-63472: vendurehq vendure: Vendure is an open-source headless commerce platform9.1 CriticalN/AN/ASep 17, 2026
CVE-2026-63461: vendurehq vendure: Vendure is an open-source headless commerce platform5.3 MediumN/AN/ASep 17, 2026
CVE-2026-63460: vendurehq vendure: Vendure is an open-source headless commerce platform7.5 HighN/AN/ASep 17, 2026
CVE-2026-63459: vendurehq vendure: Vendure is an open-source headless commerce platform8.7 HighN/AN/ASep 17, 2026
CVE-2026-61793: nuxt-modules og-image: Nuxt OG Image generates OG Images with Vue templates in NuxtN/A6.9 MediumN/ASep 17, 2026
CVE-2026-54471: Dell SmartFabric Manager: Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or…3.5 LowN/AN/ASep 17, 2026
CVE-2026-26950: Dell SmartFabric Manager: Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity…8.1 HighN/AN/ASep 17, 2026
CVE-2026-76781: Red Hat: A flaw was found in libxml25.5 MediumN/AN/ASep 17, 2026
CVE-2026-92973: pycontribs ansi2html: ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that…6.1 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-92972: sgl-project sglang: SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the…8.6 High8.8 HighN/ASep 17, 2026
CVE-2026-92971: InternLM lmdeploy: InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop…7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92970: hubzero hubzero-cms: HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows…8.8 High8.7 HighN/ASep 17, 2026
CVE-2026-92963: patriksimek vm2: vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL…5.3 Medium6.9 MediumN/ASep 17, 2026
CVE-2026-92962: patriksimek vm2: vm2 is a sandbox for running untrusted JavaScriptN/A2.1 LowN/ASep 17, 2026
CVE-2026-92961: patriksimek vm2: vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors,…7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92960: patriksimek vm2: vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing…10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92959: patriksimek vm2: vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM7.1 High7.1 HighN/ASep 17, 2026
CVE-2026-92958: patriksimek vm2: vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM8.5 High8.4 HighN/ASep 17, 2026
CVE-2026-92957: patriksimek vm2: vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny)…9.9 Critical9.4 CriticalN/ASep 17, 2026
CVE-2026-92956: patriksimek vm2: vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on…10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92955: patriksimek vm2: vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__…10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92954: patriksimek vm2: vm2 is a sandbox library for running untrusted JavaScript in Node.js8.6 High9.2 CriticalN/ASep 17, 2026
CVE-2026-92953: patriksimek vm2: vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation10.0 Critical9.3 CriticalN/ASep 17, 2026
CVE-2026-92952: patriksimek vm2: vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary6.8 Medium8.9 HighN/ASep 17, 2026
CVE-2026-92951: patriksimek vm2: vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses…9.9 Critical9.4 CriticalN/ASep 17, 2026
1076-1100 of 395331