The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-59309:Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
TitleEitWModules
CVE-2026-68580: FreeRDP: FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across…7.5 High7.7 HighN/AAug 2, 2026
CVE-2026-68579: FreeRDP: FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's…9.6 Critical8.7 HighN/AAug 2, 2026
CVE-2026-67305: FreeRDP: FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel…N/A9.4 CriticalN/AAug 1, 2026
CVE-2026-67298: FreeRDP: FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler…7.5 High8.7 HighN/AAug 1, 2026
CVE-2026-18321: ntpsec: Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd4.7 MediumN/A0%Jul 31, 2026
CVE-2026-67822: n/a: Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint9.8 CriticalN/A0%Jul 31, 2026
CVE-2026-15722: Red Hat: A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base)7.5 HighN/A1%Jul 31, 2026
CVE-2026-65423: o6 Automation open62541: An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to…8.8 High8.7 High1%Jul 30, 2026
CVE-2026-63559: o6 Automation open62541: An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to…7.5 High8.7 High0%Jul 30, 2026
CVE-2026-10535: Stack-based Buffer Overflow8.4 HighN/A0%Jul 30, 2026
CVE-2026-16529: Integer Overflow or Wraparound7.5 HighN/A0%Jul 30, 2026
CVE-2026-67248: Stack-based Buffer OverflowN/A8.7 High0%Jul 30, 2026
CVE-2026-17951: Heap-based Buffer Overflow8.8 HighN/A0%Jul 30, 2026
CVE-2026-17935: Heap-based Buffer Overflow8.8 HighN/A0%Jul 30, 2026
CVE-2026-17881: Use After Free8.8 HighN/A0%Jul 30, 2026
CVE-2026-17848: Improper Input Validation9.6 CriticalN/A0%Jul 30, 2026
CVE-2026-17758: Heap-based Buffer Overflow9.6 CriticalN/A0%Jul 30, 2026
CVE-2026-17726: Integer Overflow or Wraparound9.6 CriticalN/A0%Jul 30, 2026
CVE-2026-17717: Integer Overflow or Wraparound9.6 CriticalN/A0%Jul 30, 2026
CVE-2026-17705: Integer Overflow or Wraparound8.8 HighN/A0%Jul 30, 2026
CVE-2026-17682: Integer Overflow or Wraparound9.6 CriticalN/A0%Jul 30, 2026
CVE-2026-17680: Heap-based Buffer Overflow9.6 CriticalN/A0%Jul 30, 2026
CVE-2026-17673: Integer Overflow or Wraparound9.6 CriticalN/A0%Jul 30, 2026
CVE-2026-62946: Integer Overflow or Wraparound5.1 MediumN/A0%Jul 30, 2026
CVE-2026-13309: Stack-based Buffer Overflow6.8 MediumN/A0%Jul 29, 2026
1-25 of 26168