The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-89763: Linux: In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM teardown ordering…N/AN/AN/ASep 11, 2026
CVE-2026-89753: Linux: In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: report RCU-tasks quiescent states in…N/AN/AN/ASep 11, 2026
CVE-2026-89750: Linux: In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Clear copied tracing state…N/AN/AN/ASep 11, 2026
CVE-2026-89513: Linux: In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Fix PMU event info array size overflow…N/AN/AN/ASep 11, 2026
CVE-2026-89496: Linux: In the Linux kernel, the following vulnerability has been resolved: ocfs2: always run deallocs on copy-on-write…N/AN/AN/ASep 11, 2026
CVE-2026-89483: Linux: In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page…N/AN/AN/ASep 11, 2026
CVE-2026-89449: Linux: In the Linux kernel, the following vulnerability has been resolved: iommu: Fix dev_iommu memory leak when device_add…N/AN/AN/ASep 11, 2026
CVE-2026-80986: Linux: In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC…N/AN/AN/ASep 11, 2026
CVE-2026-80981: Linux: In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in…N/AN/AN/ASep 11, 2026
CVE-2026-80946: Linux: In the Linux kernel, the following vulnerability has been resolved: fuse: copy request headers via a stack buffer for…N/AN/AN/ASep 11, 2026
CVE-2026-18579: opajaap WP Photo Album Plus: The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…7.2 HighN/A0%Sep 11, 2026
CVE-2026-12215: xootix OTP Login & Register Woocommerce: The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in…5.3 MediumN/A0%Sep 11, 2026
CVE-2026-84908: Missing Authorization5.3 MediumN/A0%Sep 9, 2026
CVE-2026-80866: Undefined Security WeaknessN/AN/A0%Sep 4, 2026
CVE-2026-80863: Undefined Security WeaknessN/AN/A0%Sep 4, 2026
CVE-2026-80853: Undefined Security WeaknessN/AN/A0%Sep 4, 2026
CVE-2026-80817: Undefined Security WeaknessN/AN/A0%Sep 4, 2026
CVE-2026-80788: Undefined Security WeaknessN/AN/A0%Sep 4, 2026
CVE-2026-80787: Undefined Security WeaknessN/AN/A0%Sep 4, 2026
CVE-2026-81347: External Control of File Name or Path5.9 MediumN/A0%Sep 4, 2026
CVE-2026-85395: Missing Authorization7.1 High7.1 High0%Sep 3, 2026
CVE-2026-80730: Undefined Security WeaknessN/AN/A0%Sep 3, 2026
CVE-2026-80726: Undefined Security Weakness9.3 CriticalN/A0%Sep 3, 2026
CVE-2026-82524: Unrestricted Upload of File with Dangerous Type7.2 High8.6 High0%Sep 2, 2026
CVE-2026-79755: Improper Neutralization of Special Elements used in an OS Command8.0 HighN/A0%Sep 2, 2026
1-25 of 1132