The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
TitleEitWModules
CVE-2026-19995: Webkul Bagisto: A vulnerability was determined in Webkul Bagisto up to 2.4.43.5 Low5.1 MediumN/AAug 17, 2026
CVE-2026-19993: Webkul Bagisto: A vulnerability has been found in Webkul Bagisto up to 2.4.44.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19992: Orange View Limited DualSafe Password Manager & Digital Vault Extension: A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome3.1 Low1.3 LowN/AAug 17, 2026
CVE-2026-19988: Alaev SEO Tools Extension: A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome4.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19994: Webkul Bagisto: A vulnerability was found in Webkul Bagisto up to 2.4.46.3 Medium5.3 MediumN/AAug 17, 2026
CVE-2026-19986: n/a Adblock for Youtube Extension: A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome5.4 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19984: jkawamoto mcp-florence2: A flaw has been found in jkawamoto mcp-florence2 up to 0.3.136.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19978: jiantao88 android-mcp-server: A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a62925.3 Medium1.9 LowN/AAug 17, 2026
CVE-2026-50601: Acer Planet9 desktop application: A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key…N/A6.6 MediumN/AAug 17, 2026
CVE-2026-19977: EFM ipTIME A3004T: A vulnerability was detected in EFM ipTIME A3004T 14.19.010.0 Critical9.3 CriticalN/AAug 17, 2026
CVE-2026-19976: COMFAST CF-N1-S: A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.16.6 Medium2.0 LowN/AAug 17, 2026
CVE-2026-19975: Azuriom CMS: A weakness has been identified in Azuriom CMS up to 1.2.123.1 Low1.3 LowN/AAug 17, 2026
CVE-2026-19974: treefrogframework treefrog-framework: A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.25.6 Medium2.9 LowN/AAug 17, 2026
CVE-2026-19973: itsourcecode Hospital Management System: A vulnerability was found in itsourcecode Hospital Management System 1.06.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19972: itsourcecode Hospital Management System: A vulnerability has been found in itsourcecode Hospital Management System 1.06.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19970: Open Asset Import Library Assimp: A vulnerability was detected in Open Asset Import Library Assimp 17c12da6.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19969: Open Asset Import Library Assimp: A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da5.4 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19968: Open Asset Import Library Assimp: A weakness has been identified in Open Asset Import Library Assimp 17c12da4.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19967: Open Asset Import Library Assimp: A security flaw has been discovered in Open Asset Import Library Assimp 17c12da6.3 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19966: CodeCanyon TimeCamp Integration for CRM: A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.85.4 Medium2.1 LowN/AAug 17, 2026
CVE-2026-19965: n/a automad: A vulnerability was determined in automad up to 2.0.0-beta.323.7 Low2.9 LowN/AAug 17, 2026
CVE-2026-19964: Jij-Inc Jij-MCP-Server: A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.05.5 Medium2.0 LowN/AAug 17, 2026
CVE-2026-19963: Edimax EW-7478APC: A vulnerability has been found in Edimax EW-7478APC 1.047.4 High2.1 LowN/AAug 17, 2026
CVE-2026-19962: Edimax EW-7478APC: A flaw has been found in Edimax EW-7478APC 1.047.4 High2.1 LowN/AAug 17, 2026
CVE-2026-19961: Edimax EW-7478APC: A vulnerability was detected in Edimax EW-7478APC 1.049.9 Critical8.6 HighN/AAug 16, 2026
1-25 of 62308