The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
TitleEitWModules
CVE-2026-44105: Phoenix Contact: The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local…6.6 Medium5.8 MediumN/AJul 30, 2026
CVE-2026-44094: Phoenix Contact: An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure…8.6 High8.3 HighN/AJul 30, 2026
CVE-2026-67192: Xlight Xlight FTP Server: Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows…8.1 High9.2 CriticalN/AJul 29, 2026
CVE-2026-67191: Xlight Xlight FTP Server: Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote…9.8 Critical9.3 CriticalN/AJul 29, 2026
CVE-2026-54635: nessshon tonapi: pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain7.5 HighN/AN/AJul 28, 2026
CVE-2026-14837: Improper Verification of Cryptographic Signature7.8 High8.5 High0%Jul 27, 2026
CVE-2026-66035: Heap-based Buffer Overflow7.5 High7.7 High0%Jul 24, 2026
CVE-2026-66034: Out-of-bounds Read7.5 High7.7 High0%Jul 24, 2026
CVE-2026-66033: Integer Underflow (Wrap or Wraparound)7.5 High8.7 High0%Jul 24, 2026
CVE-2026-66032: Double Free8.8 High8.7 High0%Jul 24, 2026
CVE-2026-65698: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium6.0 Medium0%Jul 23, 2026
CVE-2026-65607: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium7.1 High0%Jul 23, 2026
CVE-2026-63226: Improper Restriction of Communication Channel to Intended Endpoints5.8 Medium6.9 Medium0%Jul 23, 2026
CVE-2026-57599: Improper Privilege Management6.6 MediumN/A0%Jul 22, 2026
CVE-2026-47394: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.7 High0%Jul 21, 2026
CVE-2026-59851: Incorrect Authorization8.8 HighN/A0%Jul 21, 2026
CVE-2026-59850: Use After Free4.3 MediumN/A0%Jul 21, 2026
CVE-2026-59849: Loop with Unreachable Exit Condition3.1 LowN/A0%Jul 21, 2026
CVE-2026-59848: Allocation of Resources Without Limits or Throttling5.3 MediumN/A0%Jul 21, 2026
CVE-2026-59847: Missing Ability to Patch ROM Code5.9 MediumN/A0%Jul 21, 2026
CVE-2026-59846: Improper Neutralization of Special Elements used in a Command3.9 LowN/A0%Jul 21, 2026
CVE-2026-59845: Detection of Error Condition Without Action5.3 MediumN/A0%Jul 21, 2026
CVE-2026-59844: Memory Allocation with Excessive Size Value6.5 MediumN/A0%Jul 21, 2026
CVE-2026-59843: Uncontrolled Resource Consumption6.5 MediumN/A0%Jul 21, 2026
CVE-2026-59842: Out-of-bounds Read3.7 LowN/A0%Jul 21, 2026
1-25 of 1825