The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-69190: Graylog2 graylog2-server: Graylog is a free and open log management platform6.3 MediumN/AN/ASep 21, 2026
CVE-2026-62369: kubeedge: KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…8.1 HighN/AN/ASep 21, 2026
CVE-2026-62182: kubeedge: KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…8.8 HighN/AN/ASep 21, 2026
CVE-2026-61745: InvenTree: InvenTree is an Open Source Inventory Management System4.3 MediumN/AN/ASep 21, 2026
CVE-2026-61612: ondata ckan-mcp-server: CKAN MCP Server is a tool for querying CKAN open data portals5.7 MediumN/AN/ASep 21, 2026
CVE-2026-55473: sysadminsmedia homebox: HomeBox is a home inventory and organization systemN/A6.0 MediumN/ASep 21, 2026
CVE-2026-48976: sysadminsmedia homebox: HomeBox is a home inventory and organization system8.1 HighN/AN/ASep 21, 2026
CVE-2026-48975: sysadminsmedia homebox: HomeBox is a home inventory and organization system8.1 HighN/AN/ASep 21, 2026
CVE-2026-48974: sysadminsmedia homebox: HomeBox is a home inventory and organization system5.4 MediumN/AN/ASep 21, 2026
CVE-2026-48826: sysadminsmedia homebox: HomeBox is a home inventory and organization system8.1 HighN/AN/ASep 21, 2026
CVE-2026-93012: OS Command InjectionN/AN/AN/ASep 21, 2026
CVE-2026-94449: Red Hat: A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries…7.5 HighN/AN/ASep 21, 2026
CVE-2026-84990: ntop ntopng: ntopng is a web-based network traffic monitoring application8.8 HighN/AN/ASep 21, 2026
CVE-2026-83621: ntop ntopng: ntopng is a web-based network traffic monitoring application8.1 HighN/AN/ASep 21, 2026
CVE-2026-79920: ajenti: Ajenti is a Linux & BSD modular server admin panel9.9 CriticalN/AN/ASep 21, 2026
CVE-2026-77582: tinyauthapp tinyauth: Tinyauth is an authentication and authorization serverN/A6.9 MediumN/ASep 21, 2026
CVE-2026-77561: tinyauthapp tinyauth: Tinyauth is an authentication and authorization server5.3 MediumN/AN/ASep 21, 2026
CVE-2026-77560: tinyauthapp tinyauth: Tinyauth is an authentication and authorization server8.1 HighN/AN/ASep 21, 2026
CVE-2026-76898: jgraph drawio: draw.io is a configurable diagramming and whiteboarding applicationN/A7.7 HighN/ASep 21, 2026
CVE-2026-63416: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application3.7 LowN/AN/ASep 21, 2026
CVE-2026-63373: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application4.2 MediumN/AN/ASep 21, 2026
CVE-2026-63334: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application6.8 MediumN/AN/ASep 21, 2026
CVE-2026-63116: deepstreamIO deepstream.io: deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale8.8 HighN/AN/ASep 21, 2026
CVE-2026-62987: fabiolb fabio: Fabio is an HTTP(S) and TCP router for deploying applications managed by consul5.8 MediumN/AN/ASep 21, 2026
CVE-2026-62866: TomWright dasel: Dasel is a command-line tool and library for querying, modifying, and transforming data structures6.2 MediumN/AN/ASep 21, 2026
201-225 of 788572