The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
TitleEitWModules
CVE-2026-6827: EmilStenstrom justhtml: justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling6.1 Medium5.1 MediumN/AAug 23, 2026
CVE-2026-74723: Linux: In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid…N/AN/A0%Aug 22, 2026
CVE-2026-74703: Linux: In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts When…N/AN/A0%Aug 22, 2026
CVE-2026-74702: Linux: In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpoint…N/AN/A0%Aug 22, 2026
CVE-2026-74694: Linux: In the Linux kernel, the following vulnerability has been resolved: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD…N/AN/A0%Aug 22, 2026
CVE-2026-74665: Linux: In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic XDP…N/AN/A0%Aug 22, 2026
CVE-2026-74659: Linux: In the Linux kernel, the following vulnerability has been resolved: net: bridge: mrp: fix uninitialised bytes on the…N/AN/A0%Aug 22, 2026
CVE-2026-74612: Linux: In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag…N/AN/A0%Aug 22, 2026
CVE-2026-66393: nltk: NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows…7.5 High8.7 High0%Aug 22, 2026
CVE-2026-62381: openwrt luci: luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj…6.6 Medium6.9 Medium0%Aug 22, 2026
CVE-2026-66917: joomgalleryfriends.net JoomGallery extension for Joomla: Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store…N/A8.6 High1%Aug 22, 2026
CVE-2026-3424: properfraction kk Star Ratings – Rate Post & Collect User Feedbacks: The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode…5.3 MediumN/A1%Aug 22, 2026
CVE-2026-75027: Missing Authorization5.3 MediumN/A0%Aug 22, 2026
CVE-2026-48106: Arc is an open, SQL-native time-series database for telemetryN/A8.3 High0%Aug 21, 2026
CVE-2026-53529: LeafWiki is a self-hosted wikiN/A4.8 Medium0%Aug 21, 2026
CVE-2026-54682: DiscordChatExporter saves Discord chat logs to a file8.2 HighN/A0%Aug 21, 2026
CVE-2026-35163: OctoPrint: OctoPrint provides a web interface for controlling consumer 3D printersN/A4.6 Medium0%Aug 21, 2026
CVE-2026-50278: InternationalColorConsortium iccDEV: iccDEV provides a set of libraries and tools for working with ICC color management profiles6.5 MediumN/A0%Aug 21, 2026
CVE-2026-14208: Remote Utilities Pte. Ltd. Remote Utilities Host: Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files…N/A7.3 High0%Aug 21, 2026
IBM AIX: aix_vios_advisory (CVE-2026-19449): Vulnerability in aix affects AIX8.8 HighN/A0%Aug 20, 2026
CVE-2026-74836: mtrudel bandit: Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote…N/A8.7 High0%Aug 20, 2026
CVE-2026-18420: Improperly Controlled Modification of Object Prototype Attributes8.8 High8.7 High1%Aug 20, 2026
CVE-2026-50190: Improper Neutralization of Input During Web Page GenerationN/A8.6 High0%Aug 20, 2026
CVE-2026-73254: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Aug 20, 2026
CVE-2026-63384: Integer Overflow or WraparoundN/A8.7 High0%Aug 20, 2026
1-25 of 5923