The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-90774: orhun rustypaste: rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header,…7.5 High8.7 HighN/ASep 13, 2026
CVE-2026-90773: dalance procs: procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command…3.2 Low2.4 LowN/ASep 13, 2026
CVE-2026-90772: amundsen-io amundsen-frontend: Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without…7.6 High8.3 HighN/ASep 13, 2026
CVE-2026-90771: hapijs joi: joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation…3.7 Low6.3 MediumN/ASep 13, 2026
CVE-2026-90770: openspug spug: Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates…8.8 High8.7 HighN/ASep 13, 2026
CVE-2026-90769: lfnovo open-notebook: Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated…7.7 High8.3 HighN/ASep 13, 2026
CVE-2026-90768: kevoreilly CAPEv2: CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to…8.1 High8.6 HighN/ASep 13, 2026
CVE-2026-90767: Froxlor: Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing…6.5 Medium7.1 HighN/ASep 13, 2026
CVE-2026-90562: langbot-app LangBot: LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to…8.1 High9.2 CriticalN/ASep 13, 2026
CVE-2026-90561: strapi: Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the…8.7 High9.3 CriticalN/ASep 13, 2026
CVE-2026-90513: simalexan api-lambda-send-email-ses: A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d6.5 Medium6.9 MediumN/ASep 13, 2026
CVE-2026-90509: dromara orion-visor: A weakness has been identified in dromara orion-visor up to 2.5.77.3 High5.5 MediumN/ASep 13, 2026
CVE-2026-90508: Chengdu Qilu Technology Ludashi: A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.7143.4 Low1.8 LowN/ASep 13, 2026
CVE-2026-90507: vvbbnn00 WARP-Clash-API: A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b466.3 Medium2.1 LowN/ASep 13, 2026
CVE-2026-90506: vvbbnn00 WARP-Clash-API: A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b465.0 Medium1.3 LowN/ASep 13, 2026
CVE-2026-90505: vvbbnn00 WARP-Clash-API: A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b465.0 Medium1.3 LowN/ASep 13, 2026
CVE-2026-90504: vvbbnn00 WARP-Clash-API: A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b467.3 High5.5 MediumN/ASep 13, 2026
CVE-2026-90503: Chengdu Qilu Technology Ludashi: A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.7142.3 Low1.8 LowN/ASep 13, 2026
CVE-2026-90502: stilleshan ServerStatus: A vulnerability was detected in stilleshan ServerStatus 1.0/2.03.5 Low2.0 LowN/ASep 13, 2026
CVE-2026-90501: lenve vhr: A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT6.3 Medium2.1 LowN/ASep 13, 2026
CVE-2026-90500: lenve vhr: A weakness has been identified in lenve vhr 1.0-SNAPSHOT6.3 Medium2.1 LowN/ASep 13, 2026
CVE-2026-90499: lenve vhr: A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT5.4 Medium2.1 LowN/ASep 13, 2026
CVE-2026-90498: lenve vhr: A vulnerability was identified in lenve vhr 1.0-SNAPSHOT7.3 High5.5 MediumN/ASep 13, 2026
CVE-2026-90497: Fengoffice Feng Office: A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.113.5 Low2.0 LowN/ASep 13, 2026
CVE-2026-90496: Fengoffice Feng Office: A vulnerability was found in Fengoffice Feng Office up to 3.11.13.114.7 Medium2.0 LowN/ASep 13, 2026
26-50 of 811749