The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-59309:Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
TitleEitWModules
CVE-2026-70332: Microsoft Microsoft SharePoint Online: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint…9.6 CriticalN/A0%Aug 7, 2026
CVE-2026-62870: Use After Free8.8 HighN/A1%Aug 3, 2026
CVE-2026-62826: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Jul 16, 2026
CVE-2026-54733: Improper Verification of Cryptographic SignatureN/A9.3 Critical1%Jul 16, 2026
CVE-2026-55121: Out-of-bounds Read5.5 MediumN/A0%Jul 14, 2026
CVE-2026-58277: Improper Authorization8.8 HighN/A1%Jul 14, 2026
CVE-2026-56195: Out-of-bounds Read5.5 MediumN/A0%Jul 14, 2026
CVE-2026-56192: Out-of-bounds Read5.5 MediumN/A0%Jul 14, 2026
CVE-2026-50665: Out-of-bounds Read7.8 HighN/A0%Jul 14, 2026
CVE-2026-56157: Improper Access Control5.4 MediumN/A0%Jul 14, 2026
CVE-2026-56156: Heap-based Buffer Overflow7.8 HighN/A0%Jul 14, 2026
CVE-2026-55949: Use of Uninitialized Resource7.8 HighN/A0%Jul 14, 2026
CVE-2026-55947: Heap-based Buffer Overflow7.8 HighN/A0%Jul 14, 2026
CVE-2026-55898: Out-of-bounds Read6.1 MediumN/A0%Jul 14, 2026
CVE-2026-54131: Use After Free7.8 HighN/A0%Jul 14, 2026
CVE-2026-55135: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Jul 14, 2026
CVE-2026-55052: Missing Authorization8.8 HighN/A1%Jul 14, 2026
CVE-2026-55120: Heap-based Buffer Overflow7.8 HighN/A0%Jul 14, 2026
CVE-2026-55123: Heap-based Buffer Overflow7.8 HighN/A0%Jul 14, 2026
CVE-2026-55133: Heap-based Buffer Overflow7.8 HighN/A0%Jul 14, 2026
CVE-2026-55043: Heap-based Buffer Overflow7.8 HighN/A0%Jul 14, 2026
CVE-2026-55139: Out-of-bounds Read5.5 MediumN/A0%Jul 14, 2026
CVE-2026-55042: Use of Uninitialized Resource5.5 MediumN/A0%Jul 14, 2026
CVE-2026-55130: Heap-based Buffer Overflow7.8 HighN/A0%Jul 14, 2026
CVE-2026-55128: Use After Free7.8 HighN/A0%Jul 14, 2026
1-25 of 1304