The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
TitleEitWModules
CVE-2026-85051: Google Chrome: Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary…8.8 HighN/AN/ASep 3, 2026
CVE-2026-85044: Google Chrome: Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker…N/AN/AN/ASep 3, 2026
CVE-2026-85043: Google Chrome: Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access…N/AN/AN/ASep 3, 2026
CVE-2026-82527: SciPhi-AI R2R: R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates…7.5 High8.7 HighN/ASep 3, 2026
CVE-2026-53728: medplum: Medplum is a developer platform that enables development of healthcare apps7.1 HighN/AN/ASep 3, 2026
CVE-2026-44506: medplum: Medplum is a developer platform that enables development of healthcare apps8.2 HighN/AN/ASep 3, 2026
CVE-2026-19795: IBM Qiskit SDK: IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling…6.2 MediumN/AN/ASep 3, 2026
CVE-2026-85047: Google Chrome: Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote…N/AN/AN/ASep 3, 2026
CVE-2026-85049: Google Chrome: Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code…N/AN/AN/ASep 3, 2026
CVE-2026-85042: Google Chrome: Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code…N/AN/AN/ASep 3, 2026
CVE-2026-85053: Google Chrome: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute…N/AN/AN/ASep 3, 2026
CVE-2026-85050: Google Chrome: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute…N/AN/AN/ASep 3, 2026
CVE-2026-85045: Google Chrome: Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…N/AN/AN/ASep 3, 2026
CVE-2026-85048: Google Chrome: Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the…N/AN/AN/ASep 3, 2026
CVE-2026-85046: Google Chrome: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…N/AN/AN/ASep 3, 2026
CVE-2026-85396: rubyzip: rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly…7.5 High8.7 HighN/ASep 3, 2026
CVE-2026-85395: unopim: UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any…7.1 High7.1 HighN/ASep 3, 2026
CVE-2026-85394: mpdavis python-jose: python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded…9.1 Critical9.3 CriticalN/ASep 3, 2026
CVE-2026-85393: digitalbazaar forge: node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5…7.5 High8.7 HighN/ASep 3, 2026
CVE-2026-85392: Peppermint-Lab peppermint: Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout…4.3 Medium5.3 MediumN/ASep 3, 2026
CVE-2026-85391: Peppermint-Lab peppermint: Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated…9.8 Critical9.3 CriticalN/ASep 3, 2026
CVE-2026-85390: bluewave-labs Checkmate: Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and…7.1 High7.1 HighN/ASep 3, 2026
CVE-2026-85389: worklenz: Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing…6.5 Medium7.1 HighN/ASep 3, 2026
CVE-2026-85388: worklenz: Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions,…8.1 High8.6 HighN/ASep 3, 2026
CVE-2026-85205: itsourcecode Online Medicine Delivery System: A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.06.3 Medium5.3 MediumN/ASep 3, 2026
101-125 of 383220