The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
CVE-2026-50751:Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
TitleEitWModules
CVE-2026-45309: ronf asyncssh: AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on…N/A8.2 High0%Jul 17, 2026
CVE-2026-45695: kopia: Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side…9.8 CriticalN/A0%Jul 16, 2026
CVE-2026-47829: Improper Neutralization of Argument Delimiters in a Command7.8 High7.7 High0%Jul 9, 2026
CVE-2026-60002: Use After Free9.4 CriticalN/A0%Jul 8, 2026
CVE-2026-60001: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Jul 8, 2026
CVE-2026-60000: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Jul 8, 2026
CVE-2026-59999: Use of Less Trusted Source7.5 HighN/A0%Jul 8, 2026
CVE-2026-59998: Improper Following of Specification by Caller6.5 MediumN/A0%Jul 8, 2026
CVE-2026-59997: Improper Validation of Specified Quantity in Input5.4 MediumN/A0%Jul 8, 2026
CVE-2026-59996: Relative Path Traversal5.4 MediumN/A0%Jul 8, 2026
CVE-2026-59995: Relative Path Traversal5.4 MediumN/A0%Jul 8, 2026
CVE-2026-55655: Improper Restriction of Communication Channel to Intended Endpoints6.1 MediumN/A0%Jun 23, 2026
CVE-2026-55654: Out-of-bounds Read3.7 LowN/A0%Jun 23, 2026
CVE-2026-55653: Double Free6.5 MediumN/A0%Jun 23, 2026
CVE-2026-48108: Improper Input Validation5.3 MediumN/A0%Jun 10, 2026
CVE-2026-39832: Deserialization of Untrusted Data9.1 CriticalN/A1%May 22, 2026
CVE-2026-39831: Undefined Security Weakness9.1 CriticalN/A0%May 22, 2026
CVE-2026-35414: Always-Incorrect Control Flow Implementation4.2 MediumN/A0%Apr 2, 2026
CVE-2026-35388: Unprotected Alternate Channel2.5 LowN/A0%Apr 2, 2026
CVE-2026-35387: Always-Incorrect Control Flow Implementation3.1 LowN/A0%Apr 2, 2026
CVE-2026-35386: Incorrect Behavior Order8.1 HighN/A0%Apr 2, 2026
CVE-2026-35385: Improper Preservation of Permissions8.1 HighN/A0%Apr 2, 2026
CVE-2026-0964: Improper Limitation of a Pathname to a Restricted Directory5.0 MediumN/A0%Mar 26, 2026
CVE-2026-23943: Improper Handling of Highly Compressed Data (Data Amplification)5.3 Medium6.9 Medium1%Mar 13, 2026
CVE-2026-3497: Use of Uninitialized Resource7.5 High6.9 Medium2%Mar 12, 2026
1-25 of 177