The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-73546: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.4 HighN/AN/ASep 21, 2026
CVE-2026-73513: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.5 HighN/AN/ASep 21, 2026
CVE-2026-73512: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications7.5 HighN/AN/ASep 21, 2026
CVE-2026-62247: supabase realtime: Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets6.5 MediumN/AN/ASep 21, 2026
CVE-2026-58271: Sync-in server: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing6.8 MediumN/AN/ASep 21, 2026
CVE-2026-58269: Sync-in server: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing8.1 HighN/AN/ASep 21, 2026
CVE-2026-55897: openwrt luci: luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router…8.8 HighN/AN/ASep 21, 2026
CVE-2026-55159: openwrt luci-app-adblock-fast: luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns,…8.8 HighN/AN/ASep 21, 2026
CVE-2026-54915: Tautulli: Tautulli is a Python based monitoring and tracking tool for Plex Media Server5.4 MediumN/AN/ASep 21, 2026
CVE-2026-52835: Tautulli: Tautulli is a Python based monitoring and tracking tool for Plex Media ServerN/A7.0 HighN/ASep 21, 2026
CVE-2026-50572: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications5.9 MediumN/AN/ASep 21, 2026
CVE-2026-49995: Tautulli: Tautulli is a Python based monitoring and tracking tool for Plex Media ServerN/A4.8 MediumN/ASep 21, 2026
CVE-2026-49811: Dell Command | Monitor (DCM): Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical…8.4 HighN/AN/ASep 21, 2026
CVE-2026-48521: envoyproxy envoy: Envoy is an open source edge and service proxy designed for cloud-native applications5.9 MediumN/AN/ASep 21, 2026
CVE-2026-45381: Tautulli: Tautulli is a Python based monitoring and tracking tool for Plex Media ServerN/A5.1 MediumN/ASep 21, 2026
CVE-2026-94501: jishenghua jshERP: jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows…8.8 High8.7 HighN/ASep 21, 2026
CVE-2026-94497: jishenghua jshERP: jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple…8.3 High8.7 HighN/ASep 21, 2026
CVE-2026-94496: jishenghua jshERP: jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to…8.3 High8.7 HighN/ASep 21, 2026
CVE-2026-94495: jishenghua jshERP: jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing…7.1 High7.1 HighN/ASep 21, 2026
CVE-2026-94494: jishenghua jshERP: jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other…5.0 Medium5.3 MediumN/ASep 21, 2026
CVE-2026-94414: jishenghua jshERP: jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows…5.4 Medium5.3 MediumN/ASep 21, 2026
CVE-2026-94413: jishenghua jshERP: jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve…6.5 Medium7.1 HighN/ASep 21, 2026
CVE-2026-94412: jishenghua jshERP: jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows…8.8 High8.7 HighN/ASep 21, 2026
CVE-2026-94411: jishenghua jshERP: jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows…8.8 High8.7 HighN/ASep 21, 2026
CVE-2026-94403: ColorFul iGameCenter: A weakness has been identified in ColorFul iGameCenter 1.0.3.48.8 High8.5 HighN/ASep 21, 2026
151-175 of 788572