The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
TitleEitWModules
CVE-2026-64411: Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before…N/AN/AN/AJul 25, 2026
CVE-2026-64319: Linux: In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds…N/AN/AN/AJul 25, 2026
CVE-2026-15425: yoast Yoast SEO – Advanced SEO with real-time guidance and built-in AI: The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored…6.4 MediumN/AN/AJul 25, 2026
CVE-2026-66338: Red Hat: A flaw was found in libsoup5.4 MediumN/AN/AJul 24, 2026
CVE-2026-66337: Red Hat: A flaw was found in libsoup6.5 MediumN/AN/AJul 24, 2026
CVE-2026-66033: libssh2: libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the…7.5 High8.7 HighN/AJul 24, 2026
CVE-2026-65710: nuxsmin sysPass: sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the…7.1 High7.1 HighN/AJul 24, 2026
CVE-2026-65708: nuxsmin sysPass: sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated…8.1 High8.6 HighN/AJul 24, 2026
CVE-2026-66027: kortix-ai suna: Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated…8.3 High8.7 HighN/AJul 24, 2026
CVE-2026-65693: microweber: Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated…7.2 High8.6 HighN/AJul 24, 2026
CVE-2026-66005: janhq jan: Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that…6.3 Medium5.3 MediumN/AJul 24, 2026
CVE-2026-45811: Apache Software Foundation Apache NimBLE: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE7.5 HighN/AN/AJul 24, 2026
CVE-2026-63317: Apache Software Foundation Apache OpenNLP: Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:…5.6 MediumN/A0%Jul 24, 2026
CVE-2026-49743: Imagination Technologies Graphics DDK: Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes…7.8 HighN/A0%Jul 24, 2026
WordPress Plugin: fluent-support: CVE-2026-15665: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6.4 MediumN/A0%Jul 24, 2026
CVE-2026-15464: thimpress WP Hotel Booking: The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode…6.4 MediumN/A0%Jul 24, 2026
CVE-2026-12654: paymentplugins Payment Plugins for Stripe WooCommerce: The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions…5.3 MediumN/A0%Jul 24, 2026
CVE-2026-12877: Unknown: The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user…9.1 CriticalN/A0%Jul 24, 2026
CVE-2026-16870: Snowflake: Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code…8.8 HighN/A0%Jul 24, 2026
CVE-2026-16767: Ne-Lexa php-zip: A vulnerability was detected in Ne-Lexa php-zip up to 4.0.26.5 Medium5.5 Medium0%Jul 23, 2026
CVE-2026-65694: microweber: Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows…7.5 High8.7 High1%Jul 23, 2026
CVE-2026-16765: CodeAstro Online Classroom: A vulnerability was determined in CodeAstro Online Classroom 1.07.3 High5.5 Medium0%Jul 23, 2026
CVE-2026-16764: OWASP DefectDojo: A vulnerability was identified in OWASP DefectDojo 2.59.06.3 Medium2.1 Low0%Jul 23, 2026
CVE-2026-16763: localstack serverless-localstack: A vulnerability was identified in localstack serverless-localstack up to 1.4.05.3 Medium1.9 Low1%Jul 23, 2026
CVE-2026-15630: Undefined Security WeaknessN/AN/A0%Jul 23, 2026
1-25 of 61310