The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
TitleEitWModules
CVE-2026-15928: XMLRPC-C: XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability…N/A8.2 HighN/AJul 27, 2026
CVE-2026-17501: ggml-org llama.cpp: A flaw has been found in ggml-org llama.cpp e15efe05.3 Medium6.9 MediumN/AJul 27, 2026
CVE-2026-17500: ggml-org llama.cpp: A vulnerability was detected in ggml-org llama.cpp d006858/e15efe05.3 Medium6.9 MediumN/AJul 27, 2026
CVE-2026-57990: Microsoft Microsoft Edge (Chromium-based): Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker…7.4 HighN/AN/AJul 26, 2026
CVE-2026-57989: Microsoft Microsoft Edge (Chromium-based): Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over…7.4 HighN/AN/AJul 26, 2026
CVE-2026-57978: Microsoft Microsoft Edge (Chromium-based): Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a…5.4 MediumN/AN/AJul 26, 2026
CVE-2026-17497: codexu NoteGen: NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with…8.3 HighN/AN/AJul 26, 2026
CVE-2026-17496: codexu NoteGen: NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into…8.1 HighN/AN/AJul 26, 2026
CVE-2026-17458: mf-yang openclaw-cn: A vulnerability was found in mf-yang openclaw-cn up to 0.2.16.3 Medium2.1 LowN/AJul 26, 2026
CVE-2026-17457: mf-yang openclaw-cn: A vulnerability has been found in mf-yang openclaw-cn up to 0.2.14.3 Medium2.1 LowN/AJul 26, 2026
CVE-2026-17459: perwendel spark: A vulnerability was determined in perwendel spark up to 2.9.44.3 Medium2.1 LowN/AJul 26, 2026
CVE-2026-64530: Linux: In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in…N/AN/AN/AJul 26, 2026
CVE-2024-14040: Linux: In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS…N/AN/AN/AJul 26, 2026
CVE-2026-63720: koxudaxi datamodel-code-generator: datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who…7.5 High7.5 HighN/AJul 26, 2026
CVE-2026-17434: nanocoai NanoClaw: A flaw has been found in nanocoai NanoClaw up to 2.0.646.3 Medium2.1 LowN/AJul 26, 2026
CVE-2026-17433: nanocoai NanoClaw: A vulnerability was detected in nanocoai NanoClaw up to 2.0.645.3 Medium1.9 LowN/AJul 26, 2026
CVE-2026-15962: techjewel Fluent Forms Pro Add On Pack: The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and…8.8 HighN/AN/AJul 26, 2026
CVE-2026-17432: NousResearch hermes-agent: A vulnerability was detected in NousResearch hermes-agent 2026.6.55.0 Medium1.3 LowN/AJul 26, 2026
CVE-2026-10681: zephyrproject zephyr: In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new…6.5 MediumN/AN/AJul 25, 2026
CVE-2026-66013: Authorization Bypass Through User-Controlled KeyN/A9.3 CriticalN/AJul 25, 2026
CVE-2026-66012: Missing Authorization10.0 Critical10.0 CriticalN/AJul 25, 2026
CVE-2026-66011: Missing Release of Memory after Effective Lifetime3.3 Low4.8 MediumN/AJul 25, 2026
CVE-2026-64529: Linux: In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and…N/AN/A0%Jul 25, 2026
CVE-2026-64528: Linux: In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung: Remove redundant port lock…N/AN/A0%Jul 25, 2026
CVE-2026-64527: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate VMBus packet size in receive…N/AN/A0%Jul 25, 2026
1-25 of 370431