The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
TitleEitWModules
CVE-2026-64527: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate VMBus packet size in receive…N/AN/AN/AJul 25, 2026
CVE-2026-64483: Linux: In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire: isight: bound the sample count to…N/AN/AN/AJul 25, 2026
CVE-2026-64367: Linux: In the Linux kernel, the following vulnerability has been resolved: HID: hid-goodix-spi: validate report size to…N/AN/AN/AJul 25, 2026
CVE-2026-64339: Linux: In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: bound bulk IN response length to…N/AN/AN/AJul 25, 2026
CVE-2026-64319: Linux: In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds…N/AN/AN/AJul 25, 2026
CVE-2026-64293: Linux: In the Linux kernel, the following vulnerability has been resolved: iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in…N/AN/AN/AJul 25, 2026
CVE-2026-64273: Linux: In the Linux kernel, the following vulnerability has been resolved: Input: iforce - bound the device-reported…N/AN/AN/AJul 25, 2026
CVE-2026-64268: Linux: In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the…N/AN/AN/AJul 25, 2026
CVE-2026-64267: Linux: In the Linux kernel, the following vulnerability has been resolved: fuse: avoid 32-bit prune notification count wrap…N/AN/AN/AJul 25, 2026
CVE-2026-66373: Redis: Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code…7.5 HighN/AN/AJul 25, 2026
CVE-2026-66040: FFmpeg: FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and…8.8 High8.7 HighN/AJul 24, 2026
CVE-2026-57531: milkdown: Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that…5.4 Medium5.1 MediumN/AJul 24, 2026
CVE-2026-57530: milkdown: Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and…5.4 Medium5.1 MediumN/AJul 24, 2026
CVE-2026-65623: mtrudel bandit: Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via…N/A8.7 HighN/AJul 24, 2026
CVE-2026-65693: microweber: Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated…7.2 High8.6 HighN/AJul 24, 2026
CVE-2026-64219: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and…N/AN/AN/AJul 24, 2026
CVE-2026-15401: e4jvikwp VikBooking Hotel Booking Engine & PMS: The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…7.2 HighN/A1%Jul 24, 2026
CVE-2026-15755: 100plugins Open User Map – Interactive Leaflet Maps: The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via…6.4 MediumN/A0%Jul 24, 2026
WordPress Plugin: fluent-support: CVE-2026-15665: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6.4 MediumN/A0%Jul 24, 2026
CVE-2026-15464: thimpress WP Hotel Booking: The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode…6.4 MediumN/A0%Jul 24, 2026
CVE-2026-65604: zalando skipper: Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA)…8.2 High8.8 High0%Jul 23, 2026
CVE-2026-63732: decolua 9router: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that…9.9 Critical9.4 Critical1%Jul 23, 2026
CVE-2026-15212: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Jul 23, 2026
CVE-2026-47769: Missing Authentication for Critical Function5.3 MediumN/A0%Jul 23, 2026
CVE-2026-47743: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Jul 23, 2026
1-25 of 5638