The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92932: misp sachertortephp: In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error…N/A5.1 MediumN/ASep 17, 2026
CVE-2026-92921: cjbi admin3: admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key…4.9 Medium6.9 MediumN/ASep 17, 2026
CVE-2026-92919: cjbi admin3: admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to…8.1 High7.2 HighN/ASep 17, 2026
CVE-2026-92918: cjbi admin3: admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events8.8 High8.7 HighN/ASep 17, 2026
CVE-2026-92904: Red Hat Red Hat Satellite 6: A flaw was found in the foreman_remote_execution plugin's template invocations controller4.3 MediumN/AN/ASep 17, 2026
CVE-2026-81481: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a…7.5 HighN/AN/ASep 17, 2026
CVE-2026-53681: Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.N/AN/AN/ASep 17, 2026
CVE-2026-92920: cjbi admin3: admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain…5.4 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-92925: Red Hat: A flaw was found in Redis community7.1 High6.0 MediumN/ASep 17, 2026
CVE-2026-92917: getgrav grav: Grav is a flat-file CMS7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92916: getgrav grav: Grav is a flat-file CMS7.5 High8.7 HighN/ASep 17, 2026
CVE-2026-92915: WWBN AVideo: WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in…7.3 High6.9 MediumN/ASep 17, 2026
CVE-2026-92914: WWBN AVideo: AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares…8.1 High8.6 HighN/ASep 17, 2026
CVE-2026-92913: WWBN AVideo: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number…7.4 High9.1 CriticalN/ASep 17, 2026
CVE-2026-92912: WWBN AVideo: AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish…6.5 Medium8.3 HighN/ASep 17, 2026
CVE-2026-92860: rcourtman Pulse: A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.49.1 Critical9.4 CriticalN/ASep 17, 2026
CVE-2026-90823: FatPipe Networks: FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based…9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-90822: FatPipe Networks: FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command…9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-81480: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability7.2 HighN/AN/ASep 17, 2026
CVE-2026-81479: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability5.8 MediumN/AN/ASep 17, 2026
CVE-2026-81478: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key…8.1 HighN/AN/ASep 17, 2026
CVE-2026-81477: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability7.2 HighN/AN/ASep 17, 2026
CVE-2026-81476: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special…8.1 HighN/AN/ASep 17, 2026
CVE-2026-81475: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical…8.1 HighN/AN/ASep 17, 2026
CVE-2026-81441: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical…4.0 MediumN/AN/ASep 17, 2026
1476-1500 of 509859