The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
TitleEitWModules
CVE-2026-66012: Missing Authorization10.0 Critical10.0 CriticalN/AJul 25, 2026
CVE-2026-64524: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate resolution_count and fix WIN8…N/AN/AN/AJul 25, 2026
CVE-2026-64517: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/xe/gsc: Fix double-free of managed BO in error…N/AN/AN/AJul 25, 2026
CVE-2026-64501: Linux: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and…N/AN/AN/AJul 25, 2026
CVE-2026-64499: Linux: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1119: fix PM reference leak in…N/AN/AN/AJul 25, 2026
CVE-2026-64472: Linux: In the Linux kernel, the following vulnerability has been resolved: vfio/mlx5: Fix racy bitfields and tighten struct…N/AN/AN/AJul 25, 2026
CVE-2026-64456: Linux: In the Linux kernel, the following vulnerability has been resolved: hwrng: virtio: clamp device-reported used.len at…N/AN/AN/AJul 25, 2026
CVE-2026-64452: Linux: In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free on error path…N/AN/AN/AJul 25, 2026
CVE-2026-64431: Linux: In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid calling post_write_mst_fixup() for…N/AN/AN/AJul 25, 2026
CVE-2026-64403: Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before…N/AN/AN/AJul 25, 2026
CVE-2026-64281: Linux: In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when the transport closes…N/AN/AN/AJul 25, 2026
CVE-2026-64269: Linux: In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk…N/AN/AN/AJul 25, 2026
CVE-2026-15425: yoast Yoast SEO – Advanced SEO with real-time guidance and built-in AI: The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored…6.4 MediumN/AN/AJul 25, 2026
CVE-2026-48037: kerberosmansour hulumi: Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for PulumiN/A6.3 MediumN/AJul 24, 2026
CVE-2026-65707: likeadmin-likeshop likeshop: Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract…6.5 Medium8.5 HighN/AJul 24, 2026
CVE-2026-64210: Linux: In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ…N/AN/AN/AJul 24, 2026
CVE-2026-66006: treeverse lakeFS: lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the…5.3 Medium6.9 MediumN/AJul 24, 2026
CVE-2026-12496: Loytec: Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC,…N/A8.7 HighN/AJul 24, 2026
CVE-2026-9765: Grafana Grafana IRM: Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue7.1 HighN/AN/AJul 24, 2026
CVE-2026-63317: Apache Software Foundation Apache OpenNLP: Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:…5.6 MediumN/A0%Jul 24, 2026
CVE-2026-49745: Imagination Technologies Graphics DDK: Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a…7.8 HighN/A0%Jul 24, 2026
CVE-2026-49744: Imagination Technologies Graphics DDK: Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a…7.8 HighN/A0%Jul 24, 2026
CVE-2026-16910: Red Hat: A flaw was found in Red Hat Quay's notification webhook feature5.5 MediumN/A0%Jul 24, 2026
CVE-2026-15755: 100plugins Open User Map – Interactive Leaflet Maps: The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via…6.4 MediumN/A0%Jul 24, 2026
CVE-2026-15100: wpxpo Post Grid Gutenberg Blocks – PostX: The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via…6.4 MediumN/A0%Jul 24, 2026
1-25 of 9941