The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
TitleEitWModules
CVE-2026-14290: Unknown Embed Google Photos album: The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before…N/AN/AN/AAug 14, 2026
CVE-2026-12949: Wishlist Member: The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data…9.8 CriticalN/AN/AAug 14, 2026
CVE-2026-73840: openchoreo: OpenChoreo is a complete, open-source developer platform for Kubernetes5.3 MediumN/AN/AAug 13, 2026
CVE-2026-73657: triggerdotdev trigger.dev: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows4.2 MediumN/AN/AAug 13, 2026
CVE-2026-73305: budibase: Budibase is an open-source low-code platform8.8 HighN/AN/AAug 13, 2026
CVE-2026-72853: budibase: Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row…7.6 High8.8 HighN/AAug 13, 2026
CVE-2026-72851: budibase server: Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with…10.0 Critical9.0 CriticalN/AAug 13, 2026
CVE-2026-72849: budibase server: Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that…7.7 High8.7 HighN/AAug 13, 2026
CVE-2026-72776: Fosowl AgenticSeek: AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any…9.8 Critical9.3 CriticalN/AAug 13, 2026
CVE-2026-73656: triggerdotdev trigger.dev: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows9.9 CriticalN/AN/AAug 13, 2026
CVE-2026-73651: typeorm: TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server,…5.7 MediumN/AN/AAug 13, 2026
CVE-2026-73038: NodeBB: NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to…6.1 Medium5.3 MediumN/AAug 13, 2026
CVE-2026-72777: DayuanJiang next-ai-draw-io: Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint…8.6 High7.7 HighN/AAug 13, 2026
CVE-2026-73671: Saurus Saurus CMS Community Edition: Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in…6.1 Medium5.1 MediumN/AAug 13, 2026
CVE-2026-73670: Saurus Saurus CMS Community Edition: A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators…7.2 High8.6 HighN/AAug 13, 2026
CVE-2026-73515: PostGIS: PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure…8.1 High7.2 HighN/AAug 13, 2026
CVE-2026-73514: PostGIS address_standardizer: The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write…8.8 High8.7 HighN/AAug 13, 2026
CVE-2026-73557: vllm-project vllm: vLLM is an inference and serving engine for large language modelsN/A6.3 MediumN/AAug 13, 2026
Amazon Linux AMI 2: CVE-2026-48702: Security patch for runfinch-finch (ALAS2DOCKER-2026-137)7.5 HighN/AN/AAug 13, 2026
CVE-2026-6471: n/a PostgreSQL: Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any…7.2 HighN/AN/AAug 13, 2026
CVE-2026-6470: n/a PostgreSQL: Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER…4.3 MediumN/AN/AAug 13, 2026
CVE-2026-6469: n/a PostgreSQL: Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics…3.8 LowN/AN/AAug 13, 2026
CVE-2026-6464: n/a PostgreSQL: Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as…8.1 HighN/AN/AAug 13, 2026
CVE-2026-19385: n/a PostgreSQL: Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute…8.8 HighN/AN/AAug 13, 2026
CVE-2026-18408: n/a PostgreSQL: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary…8.8 HighN/AN/AAug 13, 2026
1-25 of 10289