The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-86197: getgrav grav: Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and…N/A5.1 MediumN/ASep 5, 2026
CVE-2026-86196: getgrav grav-plugin-api: Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password…N/A8.7 HighN/ASep 5, 2026
CVE-2026-86195: getgrav grav-plugin-api: grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where…N/A8.7 HighN/ASep 5, 2026
CVE-2026-86194: getgrav grav-plugin-form: Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing…N/A6.9 MediumN/ASep 5, 2026
CVE-2026-86193: getgrav grav-plugin-api: grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing…N/A8.7 HighN/ASep 5, 2026
CVE-2026-86192: siyuan-note siyuan: SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys…6.5 Medium7.1 HighN/ASep 5, 2026
CVE-2026-86191: siyuan-note siyuan: SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint…4.3 Medium5.3 MediumN/ASep 5, 2026
CVE-2026-86190: WWBN AVideo: WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user…9.1 Critical9.3 CriticalN/ASep 5, 2026
CVE-2026-86189: WWBN AVideo: WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to…9.8 Critical9.3 CriticalN/ASep 5, 2026
CVE-2026-86188: WWBN AVideo: AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers…7.2 High6.9 MediumN/ASep 5, 2026
CVE-2026-86187: WWBN AVideo: WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator,…5.9 Medium7.4 HighN/ASep 5, 2026
CVE-2026-86186: WWBN AVideo: AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all…6.5 Medium6.3 MediumN/ASep 5, 2026
CVE-2026-86185: Bilibili Bilibili Desktop: Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote…8.0 High8.6 HighN/ASep 5, 2026
CVE-2026-86184: laradashboard: Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows…9.8 Critical9.3 CriticalN/ASep 5, 2026
CVE-2026-15550: Saturday Drive Ninja Forms - Save Progress: The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and…4.3 MediumN/AN/ASep 5, 2026
CVE-2026-12843: StellarWP LearnDash LMS: The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.65.4 MediumN/AN/ASep 5, 2026
CVE-2026-10196: getwpfunnels: The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable…9.8 CriticalN/AN/ASep 5, 2026
CVE-2025-9049: scriptsbundle Nokri – Job Board WordPress Theme: The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a…8.8 HighN/AN/ASep 5, 2026
CVE-2025-15647: artem-ogre CDT: CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge…5.5 Medium6.8 MediumN/ASep 5, 2026
CVE-2025-15614: Genivia ugrep: ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z…3.3 Low4.8 MediumN/ASep 5, 2026
CVE-2026-86178: pixelfed: Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints,…5.4 Medium5.3 MediumN/ASep 5, 2026
CVE-2026-86177: pterodactyl panel: Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing…8.8 High8.7 HighN/ASep 5, 2026
CVE-2026-86176: netbox-community netbox: NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications,…4.3 Medium5.3 MediumN/ASep 5, 2026
CVE-2026-86175: netbox-community netbox: NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses6.5 Medium7.1 HighN/ASep 5, 2026
CVE-2026-86174: makeplane plane: Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint4.3 Medium5.3 MediumN/ASep 5, 2026
1-25 of 384230