The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-94127:Critical Unauthenticated RCE in F5 BIG-IP APM
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
TitleEitWModules
CVE-2026-82259: Deserialization of Untrusted Data7.5 High8.7 High0%Aug 28, 2026
CVE-2026-82258: Concurrent Execution using Shared Resource with Improper Synchronization4.8 Medium5.9 Medium0%Aug 28, 2026
CVE-2026-82257: Improperly Controlled Modification of Object Prototype Attributes4.3 Medium5.3 Medium0%Aug 28, 2026
CVE-2026-82256: Uncontrolled Resource Consumption5.3 Medium6.9 Medium0%Aug 28, 2026
CVE-2026-82255: Insufficiently Protected Credentials6.8 Medium7.6 High0%Aug 28, 2026
CVE-2026-82254: Uncaught Exception7.5 High8.7 High0%Aug 28, 2026
CVE-2026-82253: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High0%Aug 28, 2026
CVE-2026-82252: Improper Link Resolution Before File Access7.5 High8.7 High0%Aug 28, 2026
CVE-2026-82251: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High0%Aug 28, 2026
CVE-2026-82250: Integer Underflow (Wrap or Wraparound)6.5 Medium7.1 High0%Aug 28, 2026
CVE-2026-82249: Improper Encoding or Escaping of Output3.1 Low2.3 Low0%Aug 28, 2026
CVE-2026-82248: Improper Link Resolution Before File Access5.3 Medium6.0 Medium0%Aug 28, 2026
CVE-2026-82247: Insufficiently Protected Credentials7.5 High8.7 High0%Aug 28, 2026
CVE-2026-82246: Server-Side Request Forgery (SSRF)7.1 High7.1 High0%Aug 28, 2026
CVE-2026-82245: Missing Authorization8.1 High7.2 High0%Aug 28, 2026
CVE-2026-82244: Improper Control of Generation of Code9.1 Critical9.4 Critical1%Aug 28, 2026
CVE-2026-82243: Server-Side Request Forgery (SSRF)7.6 High8.3 High0%Aug 28, 2026
CVE-2026-82242: Missing Authorization7.7 High8.3 High0%Aug 28, 2026
CVE-2026-82241: Server-Side Request Forgery (SSRF)7.1 High7.1 High0%Aug 28, 2026
CVE-2026-82240: Missing Authorization8.1 High8.6 High0%Aug 28, 2026
CVE-2026-82239: Missing Authorization8.1 High8.6 High0%Aug 28, 2026
CVE-2026-82238: Time-of-check Time-of-use (TOCTOU) Race Condition3.1 Low2.3 Low0%Aug 28, 2026
CVE-2026-82237: Incomplete Cleanup3.1 Low2.3 Low0%Aug 28, 2026
CVE-2026-82236: Incomplete Cleanup3.1 Low2.3 Low0%Aug 28, 2026
CVE-2026-82235: Uncontrolled Resource Consumption5.9 Medium8.2 High0%Aug 28, 2026
12326-12350 of 775503