The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-66626: Sonal S Sinha SKT Addons for Elementor: Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66625: WCVendors WC Vendors Marketplace: Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66624: Ludwig You WPMasterToolKit: Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66619: Tribulant Software Newsletters: Administrator SQL Injection in Newsletters <= 4.18 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66618: Flipper Code WP Maps: Administrator SQL Injection in WP Maps <= 4.9.9 versions.7.6 HighN/AN/ASep 17, 2026
CVE-2026-66617: PublishPress PublishPress Series: Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66608: Unlimited Elements: Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <=…6.4 MediumN/AN/ASep 17, 2026
CVE-2026-66580: RexTheme Product Feed Manager: Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.8.5 HighN/AN/ASep 17, 2026
CVE-2026-66579: Crocoblock. Jetimpex Inc. JetElements For Elementor: Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66578: Property Hive PropertyHive: Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66577: Crocoblock. Jetimpex Inc. JetSearch: Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66576: Crocoblock. Jetimpex Inc. JetBlocks For Elementor: Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66575: KingAddons.com King Addons for Elementor: Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.5.3 MediumN/AN/ASep 17, 2026
CVE-2026-66574: bdthemes Element Pack Elementor Addons: Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66573: Crocoblock. Jetimpex Inc. JetTabs: Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66572: Crocoblock. Jetimpex Inc. JetBlog: Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.6.5 MediumN/AN/ASep 17, 2026
CVE-2026-66571: Gabe Livan Asset CleanUp: Page Speed Booster: Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.7.1 HighN/AN/ASep 17, 2026
CVE-2026-62108: miniOrange Headless Single Sign On: Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-62104: superweby Migratico Lite: Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.10.0 CriticalN/AN/ASep 17, 2026
CVE-2026-62101: Chris Åkerfeldt Wendel EduAdmin Booking: Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-14850: MobiAPParc: The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the…N/A8.8 HighN/ASep 17, 2026
CVE-2026-92972: sgl-project sglang: SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the…8.6 High8.8 HighN/ASep 17, 2026
CVE-2026-92932: misp sachertortephp: In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error…N/A5.1 MediumN/ASep 17, 2026
CVE-2026-92921: cjbi admin3: admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key…4.9 Medium6.9 MediumN/ASep 17, 2026
CVE-2026-92919: cjbi admin3: admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to…8.1 High7.2 HighN/ASep 17, 2026
1476-1500 of 597436