The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-85999: facelessuser soupsieve: Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 45.3 MediumN/AN/ASep 17, 2026
CVE-2026-85721: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…7.5 HighN/AN/ASep 17, 2026
CVE-2026-85719: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…7.5 HighN/AN/ASep 17, 2026
CVE-2026-85718: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…5.9 MediumN/AN/ASep 17, 2026
CVE-2026-85717: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…6.8 MediumN/AN/ASep 17, 2026
CVE-2026-85715: mattiasw ExifReader: ExifReader is a JavaScript Exif information parser7.5 HighN/AN/ASep 17, 2026
CVE-2026-81868: SteeltoeOSS security-advisories: Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…6.5 MediumN/AN/ASep 17, 2026
CVE-2026-81516: SteeltoeOSS security-advisories: Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…7.5 HighN/AN/ASep 17, 2026
CVE-2026-81515: SteeltoeOSS security-advisories: Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…7.5 HighN/AN/ASep 17, 2026
CVE-2026-76834: b2evolution b2evolution CMS: b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array…8.1 High9.2 CriticalN/ASep 17, 2026
CVE-2026-76781: Red Hat: A flaw was found in libxml25.5 MediumN/AN/ASep 17, 2026
CVE-2026-75588: Mattermost: Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is…2.6 LowN/AN/ASep 17, 2026
CVE-2026-75523: SteeltoeOSS security-advisories: Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…5.9 MediumN/AN/ASep 17, 2026
CVE-2026-69197: umbraco Umbraco-CMS: Umbraco is an ASP.NET CMSN/A8.7 HighN/ASep 17, 2026
CVE-2026-61700: mariadb-corporation mariadb-connector-j: MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases3.7 LowN/AN/ASep 17, 2026
CVE-2026-56795: Dell: Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability8.2 HighN/AN/ASep 17, 2026
CVE-2026-12284: Mattermost: Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a…3.7 LowN/AN/ASep 17, 2026
CVE-2026-92987: RazrFalcon roxmltree: roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits…7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92986: siyuan-note siyuan: SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters8.8 High8.6 HighN/ASep 17, 2026
CVE-2026-92985: siyuan-note siyuan: SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the…8.8 High8.6 HighN/ASep 17, 2026
CVE-2026-92984: hubzero hubzero-cms: HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies…8.1 High8.5 HighN/ASep 17, 2026
CVE-2026-92983: InternLM lmdeploy: InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions…7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92880: n/a vgmstream: A weakness has been identified in vgmstream up to r21176.3 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-88952: team-alembic ash_authentication: Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another…N/A9.1 CriticalN/ASep 17, 2026
CVE-2026-87742: Red Hat: A flaw was found in quarkus-websockets-next7.5 HighN/AN/ASep 17, 2026
1326-1350 of 396001