The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-73551: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications5.3 MediumN/AN/ASep 21, 2026
CVE-2026-73511: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications5.3 MediumN/AN/ASep 21, 2026
CVE-2026-67827: n/a: Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote…N/AN/AN/ASep 21, 2026
CVE-2026-61647: roomi-fields notebooklm-mcp: NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content…N/A7.1 HighN/ASep 21, 2026
CVE-2026-59816: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks4.3 MediumN/AN/ASep 21, 2026
CVE-2026-58272: Sync-in server: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing5.3 MediumN/AN/ASep 21, 2026
CVE-2026-58270: Sync-in server: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing6.5 MediumN/AN/ASep 21, 2026
CVE-2026-55179: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks6.5 MediumN/AN/ASep 21, 2026
CVE-2026-55105: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks7.7 HighN/AN/ASep 21, 2026
CVE-2026-49453: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks7.0 HighN/AN/ASep 21, 2026
CVE-2026-49450: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks7.1 HighN/AN/ASep 21, 2026
CVE-2026-49449: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks2.5 LowN/AN/ASep 21, 2026
CVE-2026-46649: laurent22 joplin: Joplin is an open source note-taking and to-do application that organises notes and lists into notebooksN/A9.1 CriticalN/ASep 21, 2026
CVE-2026-85219: Thinkst Applied Research OpenCanary: Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause…3.7 LowN/AN/ASep 21, 2026
CVE-2026-81469: Dell Inventory Collector Client: Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability7.8 HighN/AN/ASep 21, 2026
CVE-2026-79320: n/a: Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtimeN/AN/AN/ASep 21, 2026
CVE-2026-79319: n/a: Stencil core 4.43.5 is vulnerable to Incorrect Access Control.N/AN/AN/ASep 21, 2026
CVE-2026-79318: n/a: web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in…N/AN/AN/ASep 21, 2026
CVE-2026-73552: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.5 HighN/AN/ASep 21, 2026
CVE-2026-73550: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.5 HighN/AN/ASep 21, 2026
CVE-2026-73549: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications5.3 MediumN/AN/ASep 21, 2026
CVE-2026-73548: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.5 HighN/AN/ASep 21, 2026
CVE-2026-73547: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.5 HighN/AN/ASep 21, 2026
CVE-2026-73546: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.4 HighN/AN/ASep 21, 2026
CVE-2026-73513: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.5 HighN/AN/ASep 21, 2026
126-150 of 788572