The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-89012: Dolibarr: Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query…6.5 Medium7.1 HighN/ASep 11, 2026
CVE-2026-88046: Improper Limitation of a Pathname to a Restricted Directory5.3 MediumN/A0%Sep 10, 2026
CVE-2026-88892: Server-Side Request Forgery (SSRF)5.0 Medium5.3 Medium0%Sep 10, 2026
CVE-2026-88890: Improper Neutralization of Special Elements used in an SQL Command8.5 High8.4 High0%Sep 10, 2026
CVE-2026-61911: Exposure of Sensitive System Information to an Unauthorized Control Sphere4.3 MediumN/A0%Sep 9, 2026
CVE-2026-87818: Improper Neutralization of Argument Delimiters in a Command6.5 Medium7.1 High0%Sep 9, 2026
CVE-2026-86729: Improper Restriction of Excessive Authentication Attempts7.4 High9.1 Critical0%Sep 8, 2026
CVE-2026-82586: Improper Protection of Alternate PathN/A8.2 High0%Sep 7, 2026
CVE-2026-4361: Server-Side Request Forgery (SSRF)5.0 MediumN/A0%Sep 5, 2026
CVE-2026-52769: Server-Side Request Forgery (SSRF)8.3 HighN/A0%Sep 5, 2026
CVE-2026-85687: External Control of File Name or Path7.5 High8.7 High0%Sep 4, 2026
CVE-2026-85155: Improper Neutralization of Special Elements used in an SQL Command7.5 High8.7 High0%Sep 3, 2026
CVE-2026-19806: Improper Authentication8.8 HighN/A0%Sep 1, 2026
CVE-2026-70449: Improper Limitation of a Pathname to a Restricted Directory5.3 MediumN/A1%Aug 31, 2026
CVE-2026-82725: Authorization Bypass Through User-Controlled KeyN/A2.3 Low0%Aug 31, 2026
CVE-2026-81853: Authorization Bypass Through User-Controlled KeyN/A2.3 Low0%Aug 31, 2026
CVE-2026-82645: Improper Verification of Cryptographic Signature8.6 High9.2 Critical0%Aug 30, 2026
CVE-2026-55785: Observable Timing Discrepancy3.7 LowN/A0%Aug 28, 2026
CVE-2026-55509: Improper Neutralization of Special Elements used in an SQL CommandN/A8.8 High0%Aug 28, 2026
CVE-2026-39944: Use of a Broken or Risky Cryptographic Algorithm8.8 HighN/A0%Aug 28, 2026
CVE-2025-30156: Use of a Broken or Risky Cryptographic Algorithm8.9 HighN/A0%Aug 28, 2026
CVE-2026-77438: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 27, 2026
CVE-2026-71054: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Aug 26, 2026
CVE-2026-46371: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Aug 26, 2026
CVE-2026-46370: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Aug 26, 2026
1-25 of 11621