The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-76501: Cisco Cisco NX-OS Software: A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of…9.8 CriticalN/AN/AOct 7, 2026
CVE-2026-76488: Cisco Cisco Application Policy Infrastructure Controller (APIC): A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could…6.5 MediumN/AN/AOct 7, 2026
CVE-2026-76486: Cisco Cisco NX-OS Software: A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as…9.8 CriticalN/AN/AOct 7, 2026
CVE-2026-76485: Cisco Cisco NX-OS Software: A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as…9.8 CriticalN/AN/AOct 7, 2026
CVE-2026-76465: Cisco Cisco NX-OS Software: A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco…9.8 CriticalN/AN/AOct 7, 2026
CVE-2026-76452: Cisco Cisco License On-Prem: A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager…4.9 MediumN/AN/AOct 7, 2026
CVE-2026-76437: Cisco Cisco License On-Prem: A vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem…4.9 MediumN/AN/AOct 7, 2026
CVE-2026-62252: sipcapture homer: Homer is open source telecom observability software9.8 CriticalN/AN/AOct 7, 2026
CVE-2026-20328: Cisco Cisco License On-Prem: A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager…9.1 CriticalN/AN/AOct 7, 2026
CVE-2026-20321: Cisco Cisco Application Policy Infrastructure Controller (APIC): A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could…6.5 MediumN/AN/AOct 7, 2026
CVE-2026-107272: gophish: Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to…4.7 Medium2.3 LowN/AOct 7, 2026
CVE-2026-107202: jonssonyan h-ui: A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper…N/AN/AN/AOct 7, 2026
CVE-2026-102258: SonicWall SMA1000: Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance…6.1 MediumN/AN/AOct 7, 2026
CVE-2026-102256: SonicWall SMA1000: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…7.8 HighN/AN/AOct 7, 2026
CVE-2026-92532: BugTracker.NET: Unrestricted file upload vulnerability in the BugTracker.NET attachment functionalityN/A7.5 HighN/AOct 7, 2026
CVE-2026-92531: BugTracker.NET: Operating system command injection vulnerability in the SVN integration component of BugTracker.NETN/A7.5 HighN/AOct 7, 2026
CVE-2025-64391: Veeam Agent for Windows: This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write…N/A4.1 MediumN/AOct 7, 2026
CVE-2026-97331: Unknown User Private Files: The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document…4.3 MediumN/AN/AOct 7, 2026
CVE-2026-97188: Unknown String locator: The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content…8.8 HighN/AN/AOct 7, 2026
CVE-2026-87782: Unknown Koinonia Link: The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a…8.8 HighN/AN/AOct 7, 2026
CVE-2026-86833: Unknown MetForm: The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them…5.4 MediumN/AN/AOct 7, 2026
CVE-2026-104678: Unknown CP Media Player: The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler,…2.7 LowN/AN/AOct 7, 2026
CVE-2026-104677: Unknown WP Coder: The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to…7.2 HighN/AN/AOct 7, 2026
CVE-2026-104653: Unknown Envira Gallery: The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display…6.8 MediumN/AN/AOct 7, 2026
CVE-2026-104652: Unknown Envira Gallery: The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before…6.8 MediumN/AN/AOct 7, 2026
1-25 of 17425
›