The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
TitleEitWModules
CVE-2026-74251: phoca.cz Phoca Cart extension for Joomla: Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.16 - The a[]…N/A9.3 CriticalN/AAug 16, 2026
CVE-2026-74578: Linux: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous…N/AN/AN/AAug 16, 2026
CVE-2024-13784: reputeinfosystems: The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object…9.8 CriticalN/AN/AAug 16, 2026
CVE-2026-2497: bestwebsoft Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress: The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}'…7.2 HighN/AN/AAug 16, 2026
CVE-2026-2357: boldthemes Bold Page Builder: The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's…6.4 MediumN/AN/AAug 16, 2026
CVE-2026-18347: themeum: The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization…4.3 MediumN/AN/AAug 16, 2026
CVE-2026-17608: aresit WP Compress – Instant Performance & Speed Optimization: The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request…6.5 MediumN/AN/AAug 16, 2026
CVE-2026-17604: themeum: The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory…4.9 MediumN/AN/AAug 16, 2026
CVE-2026-17087: wptravelengine WP Travel Engine – Tour Booking Plugin – Tour Operator Software: The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization…7.5 HighN/AN/AAug 16, 2026
CVE-2026-13424: ladela Online Scheduling and Appointment Booking System – Bookly: The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site…7.2 HighN/AN/AAug 16, 2026
CVE-2026-12998: wpmudev: The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure…5.3 MediumN/AN/AAug 16, 2026
CVE-2026-10734: infility Infility Global: The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in…7.2 HighN/AN/AAug 16, 2026
CVE-2026-9767: weblizar The School Management – Education & Learning ERP: The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via…6.5 MediumN/AN/AAug 16, 2026
CVE-2026-2283: faiyazalam User Login History: The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions…4.9 MediumN/AN/AAug 16, 2026
CVE-2026-19934: itsourcecode Hospital Management System: A vulnerability has been found in itsourcecode Hospital Management System 1.06.3 Medium2.1 LowN/AAug 16, 2026
CVE-2026-18402: brainstormforce: The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting…6.4 MediumN/AN/AAug 16, 2026
CVE-2026-18316: solacewp Solace Extra: The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing…9.1 CriticalN/AN/AAug 16, 2026
CVE-2026-17582: quantumcloud: The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including,…4.9 MediumN/AN/AAug 16, 2026
CVE-2026-17581: kilbot WCPOS – Point of Sale (POS) plugin for WooCommerce: The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the…7.2 HighN/AN/AAug 16, 2026
CVE-2026-16775: smub Smash Balloon Social Post Feed – Simple Social Feeds for WordPress: The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored…6.4 MediumN/AN/AAug 16, 2026
CVE-2026-16758: aliakro Snippet Shortcodes: The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in…6.4 MediumN/AN/AAug 16, 2026
CVE-2026-15790: emarket-design: The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and…6.4 MediumN/AN/AAug 16, 2026
CVE-2026-15604: toocheke Toocheke Companion: The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and…6.4 MediumN/AN/AAug 16, 2026
CVE-2026-15351: wcvendors: The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable…4.9 MediumN/AN/AAug 16, 2026
CVE-2026-15345: shortpixel: The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to…4.3 MediumN/AN/AAug 16, 2026
1-25 of 376554