The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
TitleEitWModules
CVE-2026-77465: BinaryMuse toml-node: toml-node is a TOML parser for Node.js and the browser7.5 HighN/AN/ASep 3, 2026
CVE-2026-71429: uhop stream-json: stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint6.2 MediumN/AN/ASep 3, 2026
CVE-2026-63376: BinaryMuse toml-node: toml-node is a TOML parser for Node.js and the browser8.2 HighN/AN/ASep 3, 2026
CVE-2026-85222: D-Link DNS-340L: A vulnerability has been found in D-Link DNS-340L 1.01B049.1 Critical8.5 HighN/ASep 3, 2026
CVE-2026-84185: Red Hat: A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption…5.9 MediumN/AN/ASep 3, 2026
CVE-2026-85207: itsourcecode Online Medicine Delivery System: A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.03.5 Low2.0 LowN/ASep 3, 2026
CVE-2026-85053: Google Chrome: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute…8.8 HighN/AN/ASep 3, 2026
CVE-2026-85052: Google Chrome: Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had…3.1 LowN/AN/ASep 3, 2026
CVE-2026-85051: Google Chrome: Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary…8.8 HighN/AN/ASep 3, 2026
CVE-2026-85050: Google Chrome: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute…9.6 CriticalN/AN/ASep 3, 2026
CVE-2026-85049: Google Chrome: Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code…8.8 HighN/AN/ASep 3, 2026
CVE-2026-85048: Google Chrome: Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the…8.3 HighN/AN/ASep 3, 2026
CVE-2026-85047: Google Chrome: Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote…9.6 CriticalN/AN/ASep 3, 2026
CVE-2026-85046: Google Chrome: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…8.8 HighN/AN/ASep 3, 2026
CVE-2026-85045: Google Chrome: Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…7.5 HighN/AN/ASep 3, 2026
CVE-2026-85044: Google Chrome: Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker…N/AN/AN/ASep 3, 2026
CVE-2026-85043: Google Chrome: Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access…N/AN/AN/ASep 3, 2026
CVE-2026-85042: Google Chrome: Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code…9.6 CriticalN/AN/ASep 3, 2026
CVE-2026-82527: SciPhi-AI R2R: R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates…7.5 High8.7 HighN/ASep 3, 2026
CVE-2026-53728: medplum: Medplum is a developer platform that enables development of healthcare apps7.1 HighN/AN/ASep 3, 2026
CVE-2026-44506: medplum: Medplum is a developer platform that enables development of healthcare apps8.2 HighN/AN/ASep 3, 2026
CVE-2026-19795: IBM Qiskit SDK: IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling…6.2 MediumN/AN/ASep 3, 2026
CVE-2026-85396: rubyzip: rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly…7.5 High8.7 HighN/ASep 3, 2026
CVE-2026-85395: unopim: UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any…7.1 High7.1 HighN/ASep 3, 2026
CVE-2026-85394: mpdavis python-jose: python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded…9.1 Critical9.3 CriticalN/ASep 3, 2026
101-125 of 383220