The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-25278: Qualcomm, Inc. Snapdragon: Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data…7.8 HighN/AN/ASep 17, 2026
CVE-2026-25275: Qualcomm, Inc. Snapdragon: Transient DOS when processing authentication frames with invalid FILS information element header lengths.7.5 HighN/AN/ASep 17, 2026
CVE-2026-25261: Qualcomm, Inc. Snapdragon: Memory corruption while processing rear sensor IOCTL calls.6.7 MediumN/AN/ASep 17, 2026
CVE-2026-24081: Qualcomm, Inc. Snapdragon: Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully…7.4 HighN/AN/ASep 17, 2026
CVE-2026-24075: Qualcomm, Inc. Snapdragon: Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper…7.8 HighN/AN/ASep 17, 2026
CVE-2026-24074: Qualcomm, Inc. Snapdragon: Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy…7.8 HighN/AN/ASep 17, 2026
CVE-2026-24073: Qualcomm, Inc. Snapdragon: Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.7.8 HighN/AN/ASep 17, 2026
CVE-2025-59607: Qualcomm, Inc. Snapdragon: Memory Corruption when copying large input data exceeds normal allocation limits.7.8 HighN/AN/ASep 17, 2026
CVE-2026-92839: Canva: Canva Desktop before v1.125.0 performed double decoding in the deeplink handler4.3 MediumN/AN/ASep 17, 2026
CVE-2026-50603: Acer Agent Service: A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSenseN/A4.9 MediumN/ASep 17, 2026
CVE-2026-86311: 10web Photo Gallery by 10Web – Mobile-Friendly Image Gallery: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site…6.4 MediumN/AN/ASep 17, 2026
CVE-2026-89064: servmask All-in-One WP Migration and Backup: The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in…5.3 MediumN/AN/ASep 17, 2026
CVE-2026-92838: GeoVision Inc. GV-Remote E-map: A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application7.8 HighN/AN/ASep 17, 2026
CVE-2026-81546: Canva Affinity: The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when…7.7 HighN/AN/ASep 17, 2026
CVE-2026-85789: Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.N/AN/AN/ASep 16, 2026
CVE-2026-61596: Authorization Bypass Through User-Controlled Key7.1 HighN/AN/ASep 16, 2026
CVE-2026-61589: Use of Less Trusted Source6.3 MediumN/AN/ASep 16, 2026
CVE-2026-61588: Exposure of Sensitive Information6.5 MediumN/AN/ASep 16, 2026
CVE-2026-65388: Apple containerization: A remote attacker who controls a container registry may be able to direct a client's token request to a host of the…N/AN/AN/ASep 16, 2026
CVE-2026-92599: hapijs joi: joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression…7.5 High8.7 HighN/ASep 16, 2026
CVE-2026-92598: nodemailer: Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the…6.5 Medium8.3 HighN/ASep 16, 2026
CVE-2026-92597: nodemailer: Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a…6.5 Medium8.3 HighN/ASep 16, 2026
CVE-2026-92595: nodemailer: Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and…5.9 Medium6.0 MediumN/ASep 16, 2026
CVE-2026-92594: craftcms cms: Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator…7.5 High8.7 HighN/ASep 16, 2026
CVE-2026-92593: craftcms cms: Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the…8.8 High8.7 HighN/ASep 16, 2026
176-200 of 526898