The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-66608: Unlimited Elements: Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <=…6.4 MediumN/AN/ASep 17, 2026
CVE-2026-66580: RexTheme Product Feed Manager: Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.8.5 HighN/AN/ASep 17, 2026
CVE-2026-66578: Property Hive PropertyHive: Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66577: Crocoblock. Jetimpex Inc. JetSearch: Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66576: Crocoblock. Jetimpex Inc. JetBlocks For Elementor: Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66575: KingAddons.com King Addons for Elementor: Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-66573: Crocoblock. Jetimpex Inc. JetTabs: Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66572: Crocoblock. Jetimpex Inc. JetBlog: Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66571: Gabe Livan Asset CleanUp: Page Speed Booster: Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.7.1 HighN/AN/ASep 17, 2026
CVE-2026-62108: miniOrange Headless Single Sign On: Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-62101: Chris Åkerfeldt Wendel EduAdmin Booking: Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-14850: MobiAPParc: The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the…N/A8.8 HighN/ASep 17, 2026
CVE-2026-92944: patriksimek vm2: vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where…9.8 Critical9.3 CriticalN/ASep 17, 2026
CVE-2026-92938: patriksimek vm2: vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin…9.9 Critical9.4 CriticalN/ASep 17, 2026
CVE-2026-92933: patriksimek vm2: vm2 is a sandbox for running untrusted Node.js code5.8 Medium6.9 MediumN/ASep 17, 2026
CVE-2026-92972: sgl-project sglang: SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the…8.6 High8.8 HighN/ASep 17, 2026
CVE-2026-92970: hubzero hubzero-cms: HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows…8.8 High8.7 HighN/ASep 17, 2026
CVE-2026-78528: BerqWP: Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-74002: wpdevelop Booking Calendar: Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-66630: PublishPress PublishPress Series: Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66619: Tribulant Software Newsletters: Administrator SQL Injection in Newsletters <= 4.18 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66579: Crocoblock. Jetimpex Inc. JetElements For Elementor: Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66574: bdthemes Element Pack Elementor Addons: Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-62104: superweby Migratico Lite: Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.10.0 CriticalN/AN/ASep 17, 2026
CVE-2026-92932: misp sachertortephp: In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error…N/A5.1 MediumN/ASep 17, 2026
1451-1475 of 509859