The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92918: cjbi admin3: admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events8.8 High8.7 High0%Sep 17, 2026
CVE-2026-92904: Red Hat Red Hat Satellite 6: A flaw was found in the foreman_remote_execution plugin's template invocations controller4.3 MediumN/A0%Sep 17, 2026
CVE-2026-81481: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a…7.5 HighN/A1%Sep 17, 2026
CVE-2026-53681: Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.N/AN/AN/ASep 17, 2026
CVE-2026-92920: cjbi admin3: admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain…5.4 Medium5.3 Medium0%Sep 17, 2026
CVE-2026-92925: Red Hat: A flaw was found in Redis community7.1 High6.0 Medium0%Sep 17, 2026
CVE-2026-92917: getgrav grav: Grav is a flat-file CMS7.5 High8.7 High0%Sep 17, 2026
CVE-2026-92916: getgrav grav: Grav is a flat-file CMS7.5 High8.7 High0%Sep 17, 2026
CVE-2026-92915: WWBN AVideo: WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in…7.3 High6.9 Medium0%Sep 17, 2026
CVE-2026-92914: WWBN AVideo: AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares…8.1 High8.6 High0%Sep 17, 2026
CVE-2026-92913: WWBN AVideo: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number…7.4 High9.1 Critical1%Sep 17, 2026
CVE-2026-92912: WWBN AVideo: AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish…6.5 Medium8.3 High0%Sep 17, 2026
CVE-2026-92860: rcourtman Pulse: A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.49.1 Critical9.4 Critical0%Sep 17, 2026
CVE-2026-90823: FatPipe Networks: FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based…9.8 CriticalN/A1%Sep 17, 2026
CVE-2026-90822: FatPipe Networks: FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command…9.8 CriticalN/A1%Sep 17, 2026
CVE-2026-81480: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability7.2 HighN/A1%Sep 17, 2026
CVE-2026-81479: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability5.8 MediumN/A0%Sep 17, 2026
CVE-2026-81478: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key…8.1 HighN/A0%Sep 17, 2026
CVE-2026-81477: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability7.2 HighN/A1%Sep 17, 2026
CVE-2026-81476: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special…8.1 HighN/A1%Sep 17, 2026
CVE-2026-81475: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical…8.1 HighN/A1%Sep 17, 2026
CVE-2026-81441: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical…4.0 MediumN/A0%Sep 17, 2026
CVE-2026-81440: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability7.3 HighN/A0%Sep 17, 2026
CVE-2026-78296: WP ManageNinja LLC FluentAuth: Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing5.3 MediumN/A0%Sep 17, 2026
CVE-2026-53679: Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.N/AN/AN/ASep 17, 2026
1501-1525 of 448515