The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
TitleEitWModules
CVE-2026-64453: Linux: In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: fix disconnect UAF in client…N/AN/AN/AJul 25, 2026
CVE-2026-64447: Linux: In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix double-free and…N/AN/AN/AJul 25, 2026
CVE-2026-64230: Linux: In the Linux kernel, the following vulnerability has been resolved: regulator: tps65219: fix irq_data.rdev not being…N/AN/AN/AJul 24, 2026
CVE-2026-49413: Incorrect Privilege Assignment7.1 HighN/A0%Jun 27, 2026
CVE-2026-53286: Undefined Security Weakness7.8 HighN/A0%Jun 26, 2026
CVE-2026-6428: Improper Neutralization of Special Elements used in an SQL Command7.6 High5.6 Medium0%Jun 13, 2026
CVE-2026-49237: Incorrect Default Permissions7.8 HighN/A0%May 28, 2026
CVE-2026-46238: Undefined Security Weakness8.8 HighN/A0%May 28, 2026
CVE-2026-46162: Double Free7.8 HighN/A0%May 28, 2026
CVE-2026-45973: Undefined Security Weakness5.5 MediumN/A0%May 27, 2026
CVE-2026-43056: Use After Free7.8 HighN/A0%May 1, 2026
CVE-2026-31745: Double Free7.8 HighN/A0%May 1, 2026
CVE-2026-31565: Improper Locking5.5 MediumN/A0%Apr 24, 2026
CVE-2026-31621: Use of Uninitialized Resource5.5 MediumN/A0%Apr 24, 2026
CVE-2026-21374: Buffer Over-read7.8 HighN/A0%Apr 6, 2026
CVE-2026-23162: Double Free7.8 HighN/A0%Feb 14, 2026
CVE-2026-23106: Undefined Security Weakness5.5 MediumN/A0%Feb 4, 2026
CVE-2025-68779: Undefined Security WeaknessN/AN/A0%Jan 13, 2026
CVE-2025-11961: Buffer Over-read1.9 LowN/A0%Dec 31, 2025
CVE-2023-54302: Undefined Security WeaknessN/AN/A0%Dec 30, 2025
CVE-2023-54292: Undefined Security WeaknessN/AN/A0%Dec 30, 2025
CVE-2023-54148: Undefined Security WeaknessN/AN/A0%Dec 24, 2025
CVE-2025-68323: Undefined Security WeaknessN/AN/A0%Dec 18, 2025
CVE-2023-53811: Undefined Security WeaknessN/AN/A0%Dec 9, 2025
CVE-2025-40238: Undefined Security WeaknessN/AN/A0%Dec 4, 2025
1-25 of 70