The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92984: hubzero hubzero-cms: HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies…8.1 High8.5 HighN/ASep 17, 2026
CVE-2026-92983: InternLM lmdeploy: InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions…7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92880: n/a vgmstream: A weakness has been identified in vgmstream up to r21176.3 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-88952: team-alembic ash_authentication: Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another…N/A9.1 CriticalN/ASep 17, 2026
CVE-2026-87742: Red Hat: A flaw was found in quarkus-websockets-next7.5 HighN/AN/ASep 17, 2026
CVE-2026-85078: sanic-org sanic: Sanic is an opensource python web server/framework6.5 MediumN/AN/ASep 17, 2026
CVE-2026-85077: sanic-org sanic: Sanic is an opensource python web server/framework8.2 HighN/AN/ASep 17, 2026
CVE-2026-81447: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation…6.8 MediumN/AN/ASep 17, 2026
CVE-2026-81446: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF)…7.4 HighN/AN/ASep 17, 2026
CVE-2026-81445: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management…7.2 HighN/AN/ASep 17, 2026
CVE-2026-80356: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an…7.3 HighN/AN/ASep 17, 2026
CVE-2026-79752: cakephp: CakePHP is a rapid development framework for PHPN/A9.2 CriticalN/ASep 17, 2026
CVE-2026-77614: opencast: Opencast is a free, open-source platform to support the management of educational audio and video content8.8 HighN/AN/ASep 17, 2026
CVE-2026-71538: CycloneDX cyclonedx-node-npm: @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projectsN/A8.5 HighN/ASep 17, 2026
CVE-2026-63472: vendurehq vendure: Vendure is an open-source headless commerce platform9.1 CriticalN/AN/ASep 17, 2026
CVE-2026-63461: vendurehq vendure: Vendure is an open-source headless commerce platform5.3 MediumN/AN/ASep 17, 2026
CVE-2026-63460: vendurehq vendure: Vendure is an open-source headless commerce platform7.5 HighN/AN/ASep 17, 2026
CVE-2026-63459: vendurehq vendure: Vendure is an open-source headless commerce platform8.7 HighN/AN/ASep 17, 2026
CVE-2026-61793: nuxt-modules og-image: Nuxt OG Image generates OG Images with Vue templates in NuxtN/A6.9 MediumN/ASep 17, 2026
CVE-2026-54471: Dell SmartFabric Manager: Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or…3.5 LowN/AN/ASep 17, 2026
CVE-2026-26950: Dell SmartFabric Manager: Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity…8.1 HighN/AN/ASep 17, 2026
CVE-2026-76781: Red Hat: A flaw was found in libxml25.5 MediumN/AN/ASep 17, 2026
CVE-2026-92973: pycontribs ansi2html: ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that…6.1 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-92972: sgl-project sglang: SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the…8.6 High8.8 HighN/ASep 17, 2026
CVE-2026-92971: InternLM lmdeploy: InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop…7.5 High8.7 HighN/ASep 17, 2026
1101-1125 of 395331