The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
TitleEitWModules
CVE-2026-77116: Unknown Brave: Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.54.3 MediumN/A0%Aug 23, 2026
CVE-2026-77003: Unknown Content Mask: The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being…2.7 LowN/A0%Aug 23, 2026
CVE-2026-16149: marc4 Security Hardener: The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,…8.8 HighN/A1%Aug 23, 2026
CVE-2026-0551: buildwps PPWP – Password Protect Pages: The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and…8.8 HighN/A1%Aug 23, 2026
CVE-2026-74722: Linux: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak in btrfs_do_encoded_write()…N/AN/A0%Aug 22, 2026
CVE-2026-74631: Linux: In the Linux kernel, the following vulnerability has been resolved: net: smc: fix splice entry lifetime imbalance in…N/AN/A0%Aug 22, 2026
CVE-2026-74626: Linux: In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on…N/AN/A0%Aug 22, 2026
CVE-2026-74623: Linux: In the Linux kernel, the following vulnerability has been resolved: net: atlantic: free stranded TX buffers on ring…N/AN/A0%Aug 22, 2026
CVE-2026-74622: Linux: In the Linux kernel, the following vulnerability has been resolved: net: atlantic: free RX pages of consumed but not…N/AN/A0%Aug 22, 2026
CVE-2026-74611: Linux: In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic…N/AN/A0%Aug 22, 2026
CVE-2026-5093: wpsoul Greenshift – animation and page builder blocks: The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of…4.3 MediumN/A0%Aug 22, 2026
CVE-2026-4561: dvankooten MC4WP: Mailchimp for WordPress: The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form…6.4 MediumN/A0%Aug 22, 2026
CVE-2026-4244: metaphorcreations Post Duplicator: The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability…4.3 MediumN/A0%Aug 22, 2026
CVE-2026-4245: metaphorcreations Post Duplicator: The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,…4.3 MediumN/A0%Aug 22, 2026
CVE-2026-3424: properfraction kk Star Ratings – Rate Post & Collect User Feedbacks: The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode…5.3 MediumN/A1%Aug 22, 2026
CVE-2026-78003: Server-Side Request Forgery (SSRF)9.8 CriticalN/A1%Aug 22, 2026
CVE-2026-16260: Unknown: The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom…6.8 MediumN/A0%Aug 22, 2026
CVE-2026-75027: Missing Authorization5.3 MediumN/A0%Aug 22, 2026
CVE-2026-76904: GeoTools is an open source Java library that provides tools for geospatial data9.8 CriticalN/A0%Aug 21, 2026
CVE-2026-61539: Eval Injection10.0 CriticalN/A1%Aug 21, 2026
CVE-2026-53572: KEDA is a Kubernetes-based Event Driven Autoscaling component5.9 MediumN/A0%Aug 21, 2026
CVE-2026-74252: j2commerce.com J2Store extension for Joomla: Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 -…N/A8.6 High0%Aug 21, 2026
CVE-2026-67361: j2commerce.com J2Store extension for Joomla: Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store…N/A6.9 Medium0%Aug 21, 2026
CVE-2026-63462: Unleash is an open-source feature management platform7.5 HighN/A0%Aug 21, 2026
CVE-2026-54071: BabelDOC is a document translation tool7.8 HighN/A0%Aug 21, 2026
1-25 of 10493