The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-94494: jishenghua jshERP: jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other…5.0 Medium5.3 MediumN/ASep 21, 2026
CVE-2026-94414: jishenghua jshERP: jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows…5.4 Medium5.3 MediumN/ASep 21, 2026
CVE-2026-94413: jishenghua jshERP: jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve…6.5 Medium7.1 HighN/ASep 21, 2026
CVE-2026-94412: jishenghua jshERP: jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows…8.8 High8.7 HighN/ASep 21, 2026
CVE-2026-94411: jishenghua jshERP: jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows…8.8 High8.7 HighN/ASep 21, 2026
CVE-2026-94403: ColorFul iGameCenter: A weakness has been identified in ColorFul iGameCenter 1.0.3.48.8 High8.5 HighN/ASep 21, 2026
CVE-2026-91167: warp-tech warpgate: Warpgate is an open source SSH, HTTPS and MySQL bastion host for LinuxN/A6.0 MediumN/ASep 21, 2026
CVE-2026-91166: warp-tech warpgate: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux5.7 MediumN/AN/ASep 21, 2026
CVE-2026-91165: warp-tech warpgate: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux2.4 LowN/AN/ASep 21, 2026
CVE-2026-91164: warp-tech warpgate: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux4.3 MediumN/AN/ASep 21, 2026
CVE-2026-82165: Dell Command | Integration Suite for System Center: Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions…5.5 MediumN/AN/ASep 21, 2026
CVE-2026-82163: Dell Command | Intel vPro Out of Band: Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability5.5 MediumN/AN/ASep 21, 2026
CVE-2026-66280: Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.N/AN/AN/ASep 21, 2026
CVE-2026-63330: warp-tech warpgate: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux7.7 HighN/AN/ASep 21, 2026
CVE-2026-63329: warp-tech warpgate: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux4.9 MediumN/AN/ASep 21, 2026
CVE-2026-61749: InvenTree: InvenTree is an Open Source Inventory Management System6.5 MediumN/AN/ASep 21, 2026
CVE-2026-61748: InvenTree: InvenTree is an Open Source Inventory Management System4.3 MediumN/AN/ASep 21, 2026
CVE-2026-61747: InvenTree: InvenTree is an Open Source Inventory Management System4.3 MediumN/AN/ASep 21, 2026
CVE-2026-61746: InvenTree: InvenTree is an Open Source Inventory Management System5.3 MediumN/AN/ASep 21, 2026
CVE-2026-61744: InvenTree: InvenTree is an Open Source Inventory Management System6.5 MediumN/AN/ASep 21, 2026
CVE-2026-58491: warp-tech warpgate: Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux9.3 CriticalN/AN/ASep 21, 2026
CVE-2026-49810: Dell Command Powershell Provider (DCPP): Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into…7.8 HighN/AN/ASep 21, 2026
CVE-2026-17052: zephyrproject zephyr: The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in…7.8 HighN/AN/ASep 21, 2026
CVE-2026-94488: Telegram Telegram Desktop: Telegram Desktop before 6.9.4 allows XSS in the HTML exporter8.2 High8.3 HighN/ASep 21, 2026
CVE-2026-92382: Red Hat: An out-of-bounds write flaw was found in usbredir4.1 MediumN/AN/ASep 21, 2026
176-200 of 788572