The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92953: patriksimek vm2: vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation10.0 Critical9.3 CriticalN/ASep 17, 2026
CVE-2026-92952: patriksimek vm2: vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary6.8 Medium8.9 HighN/ASep 17, 2026
CVE-2026-92951: patriksimek vm2: vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses…9.9 Critical9.4 CriticalN/ASep 17, 2026
CVE-2026-92950: patriksimek vm2: vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary…8.6 High9.3 CriticalN/ASep 17, 2026
CVE-2026-92949: patriksimek vm2: vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects,…4.0 Medium6.3 MediumN/ASep 17, 2026
CVE-2026-92948: patriksimek vm2: vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on…9.9 Critical9.4 CriticalN/ASep 17, 2026
CVE-2026-92947: patriksimek vm2: vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by…10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92946: patriksimek vm2: vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit…10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92945: patriksimek vm2: vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string…4.2 Medium2.3 LowN/ASep 17, 2026
CVE-2026-92944: patriksimek vm2: vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where…9.8 Critical9.3 CriticalN/ASep 17, 2026
CVE-2026-92942: patriksimek vm2: vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside…7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92941: patriksimek vm2: vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call…10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92940: patriksimek vm2: vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is…10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92939: patriksimek vm2: vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed9.9 Critical9.4 CriticalN/ASep 17, 2026
CVE-2026-92938: patriksimek vm2: vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin…9.9 Critical9.4 CriticalN/ASep 17, 2026
CVE-2026-92937: patriksimek vm2: vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process10.0 Critical10.0 CriticalN/ASep 17, 2026
CVE-2026-92936: patriksimek vm2: vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting5.8 Medium6.9 MediumN/ASep 17, 2026
CVE-2026-92935: patriksimek vm2: vm2 is a sandbox for running untrusted Node.js code9.0 Critical9.5 CriticalN/ASep 17, 2026
CVE-2026-92934: patriksimek vm2: vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited…9.0 Critical9.5 CriticalN/ASep 17, 2026
CVE-2026-92933: patriksimek vm2: vm2 is a sandbox for running untrusted Node.js code5.8 Medium6.9 MediumN/ASep 17, 2026
CVE-2026-92879: n/a vgmstream: A security flaw has been discovered in vgmstream up to r21174.3 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-90986: CODEPRESS IT Solutions LLC Visitor Traffic Real Time Statistics Pro: Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.7.1 HighN/AN/ASep 17, 2026
CVE-2026-90887: WP Inventory WP Inventory Manager: Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.7.1 HighN/AN/ASep 17, 2026
CVE-2026-89418: Google protobuf-javascript (aka google-protobuf npm package): google-protobuf contains an unbounded recursion when parsing unknown protobuf group fieldsN/A8.7 HighN/ASep 17, 2026
CVE-2026-86533: team-alembic: Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a…N/A9.1 CriticalN/ASep 17, 2026
1401-1425 of 509859