The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
TitleEitWModules
CVE-2026-72748: WWBN AVideo: AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that…9.1 Critical6.9 Medium1%Aug 11, 2026
CVE-2026-68235: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: dce100: skip non-DP stream…N/AN/A0%Aug 10, 2026
CVE-2026-68228: Linux: In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Move src_buf Removal to…N/AN/A0%Aug 10, 2026
CVE-2026-69659: Deserialization of Untrusted DataN/A5.9 Medium0%Aug 9, 2026
CVE-2026-71313: Improper Limitation of a Pathname to a Restricted Directory6.9 MediumN/A0%Aug 5, 2026
CVE-2026-55733: Allocation of Resources Without Limits or Throttling7.5 High6.9 Medium0%Aug 1, 2026
CVE-2026-67302: Divide By Zero4.3 Medium5.3 Medium0%Aug 1, 2026
CVE-2026-59920: Improper Neutralization of CRLF Sequences6.5 MediumN/A0%Jul 29, 2026
CVE-2026-59919: Improper Neutralization of CRLF Sequences5.5 MediumN/A0%Jul 29, 2026
CVE-2026-59899: Allocation of Resources Without Limits or Throttling7.5 High6.9 Medium0%Jul 29, 2026
CVE-2026-65100: Incorrect Behavior Order4.8 Medium6.3 Medium0%Jul 29, 2026
CVE-2026-59921: Improper Neutralization of CRLF Sequences6.5 MediumN/A0%Jul 28, 2026
CVE-2026-66040: Heap-based Buffer Overflow8.8 High8.7 High1%Jul 24, 2026
CVE-2026-48029: Out-of-bounds Read7.1 HighN/A0%Jul 22, 2026
CVE-2026-47709: NULL Pointer Dereference5.5 Medium6.9 Medium0%Jul 21, 2026
CVE-2026-47254: Out-of-bounds Read6.1 MediumN/A0%Jul 21, 2026
CVE-2026-47251: Out-of-bounds Read6.1 Medium6.8 Medium0%Jul 21, 2026
CVE-2026-47247: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Jul 21, 2026
CVE-2026-47178: Out-of-bounds Write7.8 HighN/A0%Jul 21, 2026
CVE-2026-47714: Integer Overflow or Wraparound6.1 MediumN/A0%Jul 21, 2026
CVE-2026-64626: Server-Side Request Forgery (SSRF)6.4 Medium5.3 Medium0%Jul 20, 2026
CVE-2026-63887: Undefined Security Weakness9.8 CriticalN/A1%Jul 19, 2026
CVE-2026-63856: Undefined Security Weakness7.8 HighN/A0%Jul 19, 2026
CVE-2026-63855: Undefined Security Weakness7.8 HighN/A0%Jul 19, 2026
CVE-2026-63854: Undefined Security Weakness7.8 HighN/A0%Jul 19, 2026
1-25 of 407