The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-8030: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and…4.3 MediumN/AN/ASep 16, 2026
CVE-2026-86475: Unknown Appointment Hour Booking: The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission…5.3 MediumN/AN/ASep 16, 2026
CVE-2026-84906: Unknown Eventin: The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is…5.3 MediumN/AN/ASep 16, 2026
CVE-2026-7514: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and…4.3 MediumN/AN/ASep 16, 2026
CVE-2026-79708: GitLab: GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and…8.5 HighN/AN/ASep 16, 2026
CVE-2026-78252: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and…8.2 HighN/AN/ASep 16, 2026
CVE-2026-73447: Arista Networks EOS: A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full…9.1 Critical9.4 CriticalN/ASep 16, 2026
CVE-2026-3855: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6,…3.1 LowN/AN/ASep 16, 2026
CVE-2026-1168: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6,…7.5 HighN/AN/ASep 16, 2026
CVE-2026-19857: Unknown Formidable Forms: The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress…4.8 MediumN/AN/ASep 16, 2026
CVE-2026-19619: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and…4.7 MediumN/AN/ASep 16, 2026
CVE-2026-19248: qt: QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted…N/A7.1 HighN/ASep 16, 2026
CVE-2026-16794: GitLab: GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and…4.3 MediumN/AN/ASep 16, 2026
CVE-2026-13407: Unknown Royal Addons for Elementor: The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted…5.4 MediumN/AN/ASep 16, 2026
CVE-2025-14871: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6,…7.5 HighN/AN/ASep 16, 2026
CVE-2024-11222: GitLab: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and…6.4 MediumN/AN/ASep 16, 2026
CVE-2026-92358: Red Hat: A flaw was found in the first broker login flow of Keycloak6.4 MediumN/AN/ASep 16, 2026
CVE-2026-89328: Unknown FluentBoards: The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges…N/AN/AN/ASep 16, 2026
CVE-2026-89327: Unknown FluentBoards: The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user…N/AN/AN/ASep 16, 2026
CVE-2026-88910: Unknown kboard: The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing…N/AN/AN/ASep 16, 2026
CVE-2026-87959: Unknown WPBot: The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI…N/AN/AN/ASep 16, 2026
CVE-2026-87907: Unknown Rox Appointment Booking: The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints…N/AN/AN/ASep 16, 2026
CVE-2026-87896: Unknown Rox Appointment Booking: The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that…N/AN/AN/ASep 16, 2026
CVE-2026-87860: Unknown Subscriptions for WooCommerce: The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that…N/AN/AN/ASep 16, 2026
CVE-2026-87854: Unknown Subscriptions for WooCommerce: The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret…N/AN/AN/ASep 16, 2026
1-25 of 507619