The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-80129: Dell: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains…6.5 MediumN/AN/ASep 7, 2026
CVE-2026-80128: Dell: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains…6.4 MediumN/AN/ASep 7, 2026
CVE-2026-79734: Dell: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains…5.9 MediumN/AN/ASep 7, 2026
CVE-2026-78487: Dell: Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains…5.5 MediumN/AN/ASep 7, 2026
CVE-2026-76560: Red Hat: A flaw was found in 389 Directory Server7.5 HighN/AN/ASep 7, 2026
CVE-2026-14444: Very Good Plugins WP Fusion (Pro): The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,…7.5 HighN/AN/ASep 7, 2026
CVE-2026-12757: icegram: The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin…6.5 MediumN/AN/ASep 7, 2026
CVE-2026-8279: masteriyo: The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on…5.3 MediumN/AN/ASep 7, 2026
CVE-2026-86451: MISP: Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through…N/A5.3 MediumN/ASep 7, 2026
CVE-2026-86441: MISP: Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation…N/A2.3 LowN/ASep 7, 2026
CVE-2026-86440: MISP: Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widgetN/A5.1 MediumN/ASep 7, 2026
CVE-2026-86435: thephpleague commonmark: commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that…7.5 High8.7 HighN/ASep 7, 2026
CVE-2026-86434: thephpleague commonmark: league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in…7.5 High8.7 HighN/ASep 7, 2026
CVE-2026-86433: thephpleague commonmark: commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where…7.5 High8.7 HighN/ASep 7, 2026
CVE-2026-86432: thephpleague commonmark: commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits…5.3 Medium6.9 MediumN/ASep 7, 2026
CVE-2026-86431: thephpleague commonmark: league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability…7.2 High6.9 MediumN/ASep 7, 2026
CVE-2026-86430: thephpleague commonmark: league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block…7.5 High8.7 HighN/ASep 7, 2026
CVE-2026-86429: thephpleague commonmark: The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing…7.5 High8.7 HighN/ASep 7, 2026
CVE-2026-86428: thephpleague commonmark: commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when…7.5 High8.7 HighN/ASep 7, 2026
CVE-2026-86427: librenms: LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows…8.8 High8.7 HighN/ASep 7, 2026
CVE-2026-86426: librenms: LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated…N/A9.2 CriticalN/ASep 7, 2026
CVE-2026-86425: ImageMagick: ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method…3.3 Low4.8 MediumN/ASep 7, 2026
CVE-2026-86424: ImageMagick: ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video…2.5 Low2.0 LowN/ASep 7, 2026
CVE-2026-86423: ImageMagick: ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList…3.3 Low4.8 MediumN/ASep 7, 2026
CVE-2026-86422: ImageMagick: ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows…3.3 Low1.0 LowN/ASep 7, 2026
26-50 of 606993