The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-82759: team-alembic ash_authentication: Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the…N/A1.8 LowN/ASep 17, 2026
CVE-2026-82723: team-alembic ash_authentication: Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of…N/A1.8 LowN/ASep 17, 2026
CVE-2026-82685: team-alembic ash_authentication: Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an…N/A7.6 HighN/ASep 17, 2026
CVE-2026-81829: Red Hat: A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by…5.3 MediumN/AN/ASep 17, 2026
CVE-2026-81637: team-alembic ash_authentication: Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a…N/A2.3 LowN/ASep 17, 2026
CVE-2026-81632: team-alembic: Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone…N/A7.2 HighN/ASep 17, 2026
CVE-2026-81453: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a…6.5 MediumN/AN/ASep 17, 2026
CVE-2026-81443: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF)…6.4 MediumN/AN/ASep 17, 2026
CVE-2026-81442: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management…8.1 HighN/AN/ASep 17, 2026
CVE-2026-80355: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF)…5.4 MediumN/AN/ASep 17, 2026
CVE-2026-80218: team-alembic ash_authentication: Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for…N/A7.6 HighN/ASep 17, 2026
CVE-2026-78528: BerqWP: Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-78295: Xagio SEO: Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.8.8 HighN/AN/ASep 17, 2026
CVE-2026-78294: Dylan Kuhn Geo Mashup: Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-78223: team-alembic ash_authentication: Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the…N/A6.9 MediumN/ASep 17, 2026
CVE-2026-74017: wpeverest User Registration: Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-74005: PublishPress PublishPress Series: Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.5.4 MediumN/AN/ASep 17, 2026
CVE-2026-74002: wpdevelop Booking Calendar: Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-74000: wp.insider Simple Membership: Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-73999: Gora Tech Cooked: Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.5.4 MediumN/AN/ASep 17, 2026
CVE-2026-71568: openshift-metal3 bmctest: In BMCtest, Ironic is started without authentication and TLS for the duration of the test5.3 MediumN/AN/ASep 17, 2026
CVE-2026-66676: MatrixAddons Easy Invoice: Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-66631: Moreconvert Team MC Woocommerce Wishlist: Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66630: PublishPress PublishPress Series: Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66628: WP Lab WP-Lister Lite for eBay: Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.7.6 HighN/AN/ASep 17, 2026
1451-1475 of 509859