The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
TitleEitWModules
CVE-2026-62432: Xen: The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct…N/AN/AN/AJul 28, 2026
CVE-2026-16774: quantumcloud: The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the…5.3 MediumN/AN/AJul 28, 2026
CVE-2026-13110: wedevs: The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and…5.3 MediumN/AN/AJul 28, 2026
CVE-2026-64548: Linux: In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: reject overflowing copy + len in…N/AN/AN/AJul 27, 2026
CVE-2026-64544: Linux: In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - fix OOB read in…N/AN/AN/AJul 27, 2026
CVE-2026-10683: zephyrproject zephyr: In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt…2.4 LowN/AN/AJul 27, 2026
CVE-2026-64644: vercel next.js: Next.js is a React framework for building full-stack web applicationsN/A6.3 MediumN/AJul 27, 2026
CVE-2026-17552: RRWO Plack::App::Prerender: Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI…N/AN/AN/AJul 27, 2026
CVE-2026-64508: Undefined Security WeaknessN/AN/A0%Jul 25, 2026
CVE-2026-64469: Undefined Security Weakness7.8 HighN/A0%Jul 25, 2026
CVE-2026-64468: Undefined Security Weakness7.8 HighN/A0%Jul 25, 2026
CVE-2026-64458: Undefined Security WeaknessN/AN/A0%Jul 25, 2026
CVE-2026-64450: Undefined Security Weakness9.1 CriticalN/A0%Jul 25, 2026
CVE-2026-64448: Undefined Security Weakness8.2 HighN/A0%Jul 25, 2026
CVE-2026-64436: Undefined Security Weakness7.1 HighN/A0%Jul 25, 2026
CVE-2026-64433: Undefined Security WeaknessN/AN/A0%Jul 25, 2026
CVE-2026-64426: Undefined Security WeaknessN/AN/A0%Jul 25, 2026
CVE-2026-64421: Undefined Security WeaknessN/AN/A0%Jul 25, 2026
CVE-2026-64294: Undefined Security WeaknessN/AN/A0%Jul 25, 2026
CVE-2026-64229: Undefined Security WeaknessN/AN/A0%Jul 24, 2026
CVE-2026-64210: Undefined Security Weakness7.5 HighN/A0%Jul 24, 2026
CVE-2026-65051: Client-Side Enforcement of Server-Side Security6.5 Medium6.9 Medium0%Jul 21, 2026
CVE-2026-64205: Undefined Security WeaknessN/AN/A0%Jul 20, 2026
CVE-2026-64190: Undefined Security WeaknessN/AN/A0%Jul 20, 2026
CVE-2026-64189: Undefined Security Weakness7.8 HighN/A0%Jul 20, 2026
1-25 of 1029