The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
TitleEitWModules
CVE-2026-13712: Unknown Divi: The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before…N/AN/A0%Aug 16, 2026
CVE-2026-73052: siyuan-note siyuan: SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option…9.0 Critical9.4 Critical0%Aug 15, 2026
CVE-2026-73050: siyuan-note siyuan: SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing…9.0 Critical9.4 Critical0%Aug 15, 2026
CVE-2026-73043: siyuan-note siyuan: SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which…9.0 Critical9.4 Critical0%Aug 15, 2026
CVE-2026-73635: Apache Software Foundation Apache Struts: Allocation of resources without limits or throttling vulnerability in Apache StrutsN/AN/A0%Aug 15, 2026
CVE-2026-14230: Unknown ECS: The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater…N/AN/A0%Aug 15, 2026
CVE-2026-14484: pietror91 RapiSafe – Secure Multi File Upload for Contact Form 7: The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file…9.1 CriticalN/A1%Aug 15, 2026
CVE-2026-50029: sunnyadn js-toml: js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in…5.3 MediumN/A0%Aug 14, 2026
CVE-2026-19880: QOS.CH Sarl Logback-classic: Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal…N/A6.3 Medium0%Aug 14, 2026
CVE-2026-53472: A flaw was found in migration-planner6.3 MediumN/A0%Aug 14, 2026
CVE-2026-19829: 648540858 wvp-GB28181-pro: A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-202601074.3 Medium2.1 Low0%Aug 14, 2026
CVE-2026-19828: 648540858 wvp-GB28181-pro: A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-202601076.3 Medium2.1 Low0%Aug 14, 2026
CVE-2026-19827: alldatacenter alldata: A flaw has been found in alldatacenter alldata up to 0.6.85.3 Medium5.5 Medium0%Aug 14, 2026
CVE-2026-19826: alldatacenter alldata: A vulnerability was detected in alldatacenter alldata up to 0.6.87.3 High5.5 Medium0%Aug 14, 2026
CVE-2026-14290: Unknown Embed Google Photos album: The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before…6.8 MediumN/A0%Aug 14, 2026
CVE-2026-19763: DTStack Taier: A vulnerability was determined in DTStack Taier 1.4.03.8 Low5.1 Medium0%Aug 14, 2026
CVE-2026-19762: DTStack Taier: A vulnerability was found in DTStack Taier 1.4.07.3 High5.5 Medium0%Aug 14, 2026
CVE-2026-19761: DTStack Taier: A vulnerability has been found in DTStack Taier 1.4.04.7 Medium5.1 Medium0%Aug 14, 2026
CVE-2026-19758: dromara lamp-cloud: A vulnerability was determined in dromara lamp-cloud up to 5.10.07.3 High5.5 Medium0%Aug 14, 2026
CVE-2026-19757: Dromara lamp-cloud: A vulnerability was found in Dromara lamp-cloud up to 5.10.07.3 High5.5 Medium0%Aug 14, 2026
CVE-2026-19756: Dromara lamp-cloud: A vulnerability has been found in Dromara lamp-cloud up to 5.10.06.3 Medium2.1 Low0%Aug 13, 2026
CVE-2026-73428: basecamp trix: Trix is a what-you-see-is-what-you-get rich text editor for everyday writing4.6 MediumN/A0%Aug 13, 2026
CVE-2026-18741: Improper Neutralization of Input During Web Page Generation4.8 Medium4.6 Medium0%Aug 13, 2026
CVE-2026-18249: Improper Privilege Management8.4 HighN/A0%Aug 13, 2026
CVE-2026-73531: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Aug 13, 2026
1-25 of 15012