The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-90982: @fastify/static: @fastify/static is a Fastify plugin that serves static files from a configured root directory5.3 MediumN/AN/ASep 17, 2026
CVE-2026-44940: SUSE SUSE Observability: The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or…5.7 MediumN/AN/ASep 17, 2026
CVE-2026-91019: The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored…N/AN/AN/ASep 17, 2026
CVE-2026-91016: The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published…N/AN/AN/ASep 17, 2026
CVE-2026-91015: The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX…N/AN/AN/ASep 17, 2026
CVE-2026-91014: The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of…N/AN/AN/ASep 17, 2026
CVE-2026-91011: The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites…N/AN/AN/ASep 17, 2026
CVE-2026-91010: The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check…N/AN/AN/ASep 17, 2026
CVE-2026-91009: The Active Woot Products Tables for WooCommerceN/AN/AN/ASep 17, 2026
CVE-2026-91008: The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization…N/AN/AN/ASep 17, 2026
CVE-2026-90923: The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing…N/AN/AN/ASep 17, 2026
CVE-2026-90922: The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported…N/AN/AN/ASep 17, 2026
CVE-2026-88904: The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests…N/AN/AN/ASep 17, 2026
CVE-2026-88795: The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely,…N/AN/AN/ASep 17, 2026
CVE-2026-88792: The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding…N/AN/AN/ASep 17, 2026
CVE-2026-87836: The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to…N/AN/AN/ASep 17, 2026
CVE-2026-87786: The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before…N/AN/AN/ASep 17, 2026
CVE-2026-86824: The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy…N/AN/AN/ASep 17, 2026
CVE-2026-86788: The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the…N/AN/AN/ASep 17, 2026
CVE-2026-86710: The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued,…N/AN/AN/ASep 17, 2026
CVE-2026-86709: The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication…N/AN/AN/ASep 17, 2026
CVE-2026-86707: The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is…N/AN/AN/ASep 17, 2026
CVE-2026-86446: The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is…N/AN/AN/ASep 17, 2026
CVE-2026-85130: The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for…N/AN/AN/ASep 17, 2026
CVE-2026-85128: The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration…N/AN/AN/ASep 17, 2026
1-25 of 447834