The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-79113: aswf OpenAPV: OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.N/A5.1 MediumN/AOct 3, 2026
CVE-2026-103631: Google Chrome: Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code…N/AN/AN/AOct 2, 2026
CVE-2026-103629: Google Chrome: Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data…4.3 MediumN/AN/AOct 2, 2026
CVE-2026-103621: Google Chrome: Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin…4.3 MediumN/AN/AOct 2, 2026
CVE-2026-83632: Apache Software Foundation Apache Thrift: Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow…N/A9.2 CriticalN/AOct 2, 2026
CVE-2026-66837: Apache Software Foundation Apache Thrift: Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindingsN/A8.7 HighN/AOct 2, 2026
CVE-2026-104611: Tenda AC9: A vulnerability was detected in Tenda AC9 15.03.02.139.1 Critical8.5 HighN/AOct 2, 2026
CVE-2026-104610: Tenda: A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon10.0 Critical9.3 CriticalN/AOct 2, 2026
CVE-2026-93925: Apache Software Foundation Apache Thrift: Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocolN/A8.7 HighN/AOct 2, 2026
CVE-2026-91135: Apache Software Foundation Apache Thrift: Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransportN/A9.2 CriticalN/AOct 2, 2026
CVE-2026-86325: Moxa: A stack-based buffer overflow vulnerability exists in protocol gateways' account management interfaceN/A9.4 CriticalN/AOct 2, 2026
CVE-2026-103552: Apache Software Foundation Apache Directory LDAP API: Stack Overflow vulnerability in Apache Directory LDAP API7.3 HighN/A0%Oct 2, 2026
CVE-2026-103600: Legion of the Bouncy Castle Inc. bc-csharp: Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle IncN/A8.7 High0%Oct 2, 2026
CVE-2026-102514: Out-of-bounds WriteN/A8.4 High0%Oct 1, 2026
CVE-2026-8618: TP-Link Systems Inc. Deco M9 Plus V2: A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to…N/A7.7 High0%Oct 1, 2026
Apache HTTPD: CVE-2026-93546: Integer Overflow or Wraparound8.8 HighN/A0%Oct 1, 2026
CVE-2026-63292: Stack-based Buffer Overflow7.5 HighN/A1%Oct 1, 2026
CVE-2026-12627: Stack-based Buffer Overflow9.8 CriticalN/A0%Oct 1, 2026
CVE-2026-102505: Incorrect Calculation of Buffer Size6.3 MediumN/A0%Oct 1, 2026
CVE-2026-102504: Memory Allocation with Excessive Size Value7.5 HighN/A0%Oct 1, 2026
CVE-2026-103680: Out-of-bounds Write3.1 LowN/A0%Oct 1, 2026
CVE-2026-103531: Stack-based Buffer Overflow5.5 Medium5.1 Medium0%Oct 1, 2026
CVE-2026-101283: Heap-based Buffer OverflowN/A9.2 Critical0%Sep 30, 2026
CVE-2026-103500: Undefined Security WeaknessN/AN/A0%Sep 30, 2026
CVE-2026-47575: Out-of-bounds Write7.8 HighN/A0%Sep 30, 2026
1-25 of 27733
›