The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
TitleEitWModules
CVE-2026-67244: ASUSTOR Inc. ADM: A format string vulnerability was found in the Notification OAuth settings of ADMN/A8.6 HighN/AJul 30, 2026
CVE-2026-48449: Adobe Adobe Campaign Classic: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…10.0 CriticalN/AN/AJul 30, 2026
CVE-2026-48448: Adobe Adobe Campaign Classic: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…8.6 HighN/AN/AJul 30, 2026
CVE-2026-1982: mohammadr3z المنتور فارسی: The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to,…5.3 MediumN/AN/AJul 30, 2026
CVE-2026-18188: ASUSTOR Inc. ADM: A format string vulnerability was found in the Rsync Backup on the ADMN/A7.1 HighN/AJul 30, 2026
CVE-2026-18187: ASUSTOR Inc. ADM: A format string vulnerability was found in the Internal Backup on the ADMN/A7.1 HighN/AJul 30, 2026
CVE-2026-18186: ASUSTOR Inc. ADM: A stored format string vulnerability was found in the FTP Backup on the ADMN/A7.1 HighN/AJul 30, 2026
CVE-2026-16092: labelblanc Improved Save Button: The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field…6.5 MediumN/AN/AJul 30, 2026
CVE-2026-16727: ASUS Armoury Crate: Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate…N/A7.3 HighN/AJul 30, 2026
CVE-2026-15929: LG Electronics SmartShare: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics…N/A7.1 HighN/AJul 30, 2026
CVE-2026-59952: open-circle valibot: Valibot helps validate data using a schemaN/A6.9 MediumN/AJul 30, 2026
CVE-2026-18019: Google Chrome: Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak…N/AN/AN/AJul 30, 2026
CVE-2026-18018: Google Chrome: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to…N/AN/AN/AJul 30, 2026
CVE-2026-18017: Google Chrome: Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code…N/AN/AN/AJul 30, 2026
CVE-2026-18016: Google Chrome: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote…N/AN/AN/AJul 30, 2026
CVE-2026-18015: Google Chrome: Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to…N/AN/AN/AJul 30, 2026
CVE-2026-18014: Google Chrome: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote…N/AN/AN/AJul 30, 2026
CVE-2026-18013: Google Chrome: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker…N/AN/AN/AJul 30, 2026
CVE-2026-18012: Google Chrome: Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code…N/AN/AN/AJul 30, 2026
CVE-2026-18011: Google Chrome: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker…N/AN/AN/AJul 30, 2026
CVE-2026-18010: Google Chrome: Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform…N/AN/AN/AJul 30, 2026
CVE-2026-18009: Google Chrome: Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote…N/AN/AN/AJul 30, 2026
CVE-2026-18008: Google Chrome: Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform…N/AN/AN/AJul 30, 2026
CVE-2026-18007: Google Chrome: Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to…N/AN/AN/AJul 30, 2026
CVE-2026-18006: Google Chrome: Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had…N/AN/AN/AJul 30, 2026
1-25 of 371801