The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
TitleEitWModules
CVE-2026-76649: TP-Link System Inc. TL-WR841N v14: A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action…N/A5.3 Medium0%Aug 28, 2026
CVE-2026-75118: TP-Link Systems Inc. TL-MR100 v3.20: A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100…N/A8.7 High0%Aug 28, 2026
CVE-2026-55891: PrivateBin: PrivateBin is an online pastebin where the server has zero knowledge of pasted data0.0 NoneN/A0%Aug 28, 2026
CVE-2026-55763: klever-io klever-go: Klever-Go is the Go implementation of the Klever blockchain protocolN/A8.7 High0%Aug 28, 2026
CVE-2026-55696: PrivateBin: PrivateBin is an online pastebin where the server has zero knowledge of pasted data4.3 MediumN/A0%Aug 28, 2026
CVE-2026-55678: Basekick-Labs arc: Arc is an open, SQL-native time-series database for telemetryN/A6.9 Medium0%Aug 28, 2026
CVE-2026-51665: n/a: Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated…N/AN/A0%Aug 28, 2026
CVE-2026-51664: n/a: Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated…N/AN/A0%Aug 28, 2026
CVE-2026-51663: n/a: Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated…N/AN/A0%Aug 28, 2026
CVE-2026-51662: n/a: Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…N/AN/A0%Aug 28, 2026
CVE-2026-51661: n/a: Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…N/AN/A0%Aug 28, 2026
CVE-2026-3686: IBM Cloud Pak for Data System: IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper…6.2 MediumN/A0%Aug 28, 2026
CVE-2026-3627: IBM Concert: IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection9.1 CriticalN/A1%Aug 28, 2026
CVE-2026-22056: NetApp StorageGRID: StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are…N/A2.3 Low0%Aug 28, 2026
CVE-2026-19295: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands…9.9 CriticalN/A1%Aug 28, 2026
CVE-2026-19294: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's…6.4 MediumN/A0%Aug 28, 2026
CVE-2026-19286: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper…9.8 CriticalN/A1%Aug 28, 2026
CVE-2026-18904: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject…8.2 HighN/A0%Aug 28, 2026
CVE-2026-18899: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.7.5 HighN/A0%Aug 28, 2026
CVE-2026-18891: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive…8.2 HighN/A0%Aug 28, 2026
CVE-2026-18729: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to…8.8 HighN/A0%Aug 28, 2026
CVE-2026-18545: IBM Langflow OSS: IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF)4.3 MediumN/A0%Aug 28, 2026
CVE-2026-18527: IBM Administration Runtime Expert for i: IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker…9.9 CriticalN/A0%Aug 28, 2026
CVE-2026-17203: IBM Administration Runtime Expert for i: IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive…7.5 HighN/A0%Aug 28, 2026
IBM AIX: aix_vios_advisory (CVE-2026-16821): Vulnerability in aix affects AIX7.0 HighN/A0%Aug 28, 2026
326-350 of 383571