The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-78294: Dylan Kuhn Geo Mashup: Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-78223: team-alembic ash_authentication: Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the…N/A6.9 MediumN/ASep 17, 2026
CVE-2026-74017: wpeverest User Registration: Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-74005: PublishPress PublishPress Series: Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.5.4 MediumN/AN/ASep 17, 2026
CVE-2026-74002: wpdevelop Booking Calendar: Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-74000: wp.insider Simple Membership: Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-73999: Gora Tech Cooked: Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.5.4 MediumN/AN/ASep 17, 2026
CVE-2026-71568: openshift-metal3 bmctest: In BMCtest, Ironic is started without authentication and TLS for the duration of the test5.3 MediumN/AN/ASep 17, 2026
CVE-2026-66676: MatrixAddons Easy Invoice: Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-66631: Moreconvert Team MC Woocommerce Wishlist: Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66630: PublishPress PublishPress Series: Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66628: WP Lab WP-Lister Lite for eBay: Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66626: Sonal S Sinha SKT Addons for Elementor: Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66625: WCVendors WC Vendors Marketplace: Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66624: Ludwig You WPMasterToolKit: Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66619: Tribulant Software Newsletters: Administrator SQL Injection in Newsletters <= 4.18 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66618: Flipper Code WP Maps: Administrator SQL Injection in WP Maps <= 4.9.9 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66617: PublishPress PublishPress Series: Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66608: Unlimited Elements: Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <=…6.4 MediumN/AN/ASep 17, 2026
CVE-2026-66580: RexTheme Product Feed Manager: Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.8.5 HighN/AN/ASep 17, 2026
CVE-2026-66579: Crocoblock. Jetimpex Inc. JetElements For Elementor: Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66578: Property Hive PropertyHive: Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66577: Crocoblock. Jetimpex Inc. JetSearch: Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66576: Crocoblock. Jetimpex Inc. JetBlocks For Elementor: Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66575: KingAddons.com King Addons for Elementor: Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.5.3 MediumN/AN/ASep 17, 2026
1426-1450 of 509859