The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-50605: Acer Agent Serivce: A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSenseN/A7.4 HighN/ASep 17, 2026
CVE-2026-91017: Unknown Robokassa payment gateway for Woocommerce: The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of…3.7 LowN/AN/ASep 17, 2026
CVE-2026-90982: @fastify/static: @fastify/static is a Fastify plugin that serves static files from a configured root directory5.3 MediumN/AN/ASep 17, 2026
CVE-2026-87963: Unknown Yo: The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before…8.6 HighN/AN/ASep 17, 2026
CVE-2026-86801: Unknown To Do List Member: The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress…8.8 HighN/AN/ASep 17, 2026
CVE-2026-44940: SUSE SUSE Observability: The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or…5.7 MediumN/AN/ASep 17, 2026
CVE-2026-91019: Unknown Event Booking Manager for WooCommerce: The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored…4.9 MediumN/AN/ASep 17, 2026
CVE-2026-91016: Unknown Motors: The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published…5.3 MediumN/AN/ASep 17, 2026
CVE-2026-91015: Unknown Master Addons for Elementor: The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX…5.3 MediumN/AN/ASep 17, 2026
CVE-2026-91014: Unknown Realtyna Organic IDX plugin + WPL Real Estate: The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of…7.1 HighN/AN/ASep 17, 2026
CVE-2026-91011: Unknown EWWW Image Optimizer: The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites…6.8 MediumN/AN/ASep 17, 2026
CVE-2026-91010: Unknown Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms: The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check…4.3 MediumN/AN/ASep 17, 2026
CVE-2026-91009: Unknown Active Woot Products Tables for WooCommerce. 100% FREE: The Active Woot Products Tables for WooCommerce4.3 MediumN/AN/ASep 17, 2026
CVE-2026-91008: Unknown Event Booking Manager for WooCommerce: The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization…3.7 LowN/AN/ASep 17, 2026
CVE-2026-90923: Unknown Autopay: The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing…6.5 MediumN/AN/ASep 17, 2026
CVE-2026-90922: Unknown Paid Membership Subscriptions: The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported…5.3 MediumN/AN/ASep 17, 2026
CVE-2026-88904: Unknown PuppyFW: The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests…8.8 HighN/AN/ASep 17, 2026
CVE-2026-88795: Unknown wpShopGermany IT-RECHT KANZLEI: The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely,…9.0 CriticalN/AN/ASep 17, 2026
CVE-2026-88792: Unknown Dictionary: The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding…8.8 HighN/AN/ASep 17, 2026
CVE-2026-87836: Unknown Comments Import & Export: The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to…2.7 LowN/AN/ASep 17, 2026
CVE-2026-87786: Unknown Dewa Kirim: The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before…8.8 HighN/AN/ASep 17, 2026
CVE-2026-86824: Unknown Newsletter: The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy…4.8 MediumN/AN/ASep 17, 2026
CVE-2026-86788: Unknown HT Mega Addons for Elementor: The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the…6.8 MediumN/AN/ASep 17, 2026
CVE-2026-86710: Unknown Login with QR: The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued,…9.8 CriticalN/AN/ASep 17, 2026
CVE-2026-86709: Unknown The Pressengine: The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication…9.8 CriticalN/AN/ASep 17, 2026
1526-1550 of 509859