The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
CVE-2026-50751:Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
TitleEitWModules
CVE-2026-14551: servereye GmbH servereye Windows Agent (Sensorhub): The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are…8.8 HighN/AN/AJul 22, 2026
CVE-2026-16473: Red Hat: A flaw was found in the sbc library (BlueZ SBC codec)4.3 MediumN/AN/AJul 22, 2026
CVE-2026-63264: joomshopping.com JoomShopping extension for Joomla: The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.N/A5.3 MediumN/AJul 22, 2026
CVE-2026-2406: Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System: Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and…6.5 MediumN/AN/AJul 22, 2026
CVE-2026-15787: brainstormforce Ultimate Addons for Elementor: The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu…6.4 MediumN/AN/AJul 22, 2026
CVE-2026-63048: joomlack.fr Page Builder CK extension for Joomla: The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.N/A9.4 CriticalN/AJul 22, 2026
CVE-2026-63047: joomdonation.com Events Booking extension for Joomla: The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to…N/AN/AN/AJul 22, 2026
CVE-2026-45820: 101arrowz fflate: fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync()N/A6.6 MediumN/AJul 22, 2026
CVE-2026-3821: SMCI: Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI8.8 HighN/AN/AJul 22, 2026
CVE-2026-14322: Unknown Timetics: The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created…N/AN/AN/AJul 22, 2026
CVE-2026-12987: Unknown Events Manager: The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using…N/AN/AN/AJul 22, 2026
CVE-2026-12968: Unknown Product Addons and Product Options With Custom Fields: The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an…N/AN/AN/AJul 22, 2026
CVE-2026-15802: Chimpstudio WP Foodbakery: The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…8.1 HighN/AN/AJul 22, 2026
CVE-2026-56844: Veeam Backup and Replication: A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate…N/A8.4 HighN/AJul 22, 2026
CVE-2026-16492: umijs umi: A weakness has been identified in umijs umi up to 4.6.635.5 Medium2.0 LowN/AJul 22, 2026
CVE-2026-16490: itsourcecode Hospital Management System: A security flaw has been discovered in itsourcecode Hospital Management System 1.06.3 Medium2.1 LowN/AJul 22, 2026
CVE-2026-63263: Elastic Elasticsearch: Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data…6.5 MediumN/AN/AJul 22, 2026
CVE-2026-63262: Elastic Kibana: Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied…4.3 MediumN/AN/AJul 22, 2026
CVE-2026-16489: n/a jsforce: A vulnerability was identified in jsforce up to 3.10.165.3 Medium1.9 LowN/AJul 22, 2026
CVE-2026-16488: QUSETIONS MiniCode-Python: A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.05.0 Medium1.3 LowN/AJul 22, 2026
CVE-2026-63261: Elastic Kibana: Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)6.5 MediumN/AN/AJul 21, 2026
CVE-2026-63260: Elastic Kibana: Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)6.5 MediumN/AN/AJul 21, 2026
CVE-2026-63259: Elastic Kibana: Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via…4.3 MediumN/AN/AJul 21, 2026
CVE-2026-63145: Elastic Kibana: Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification…4.3 MediumN/AN/AJul 21, 2026
CVE-2026-63144: Elastic Elasticsearch: Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request…6.5 MediumN/AN/AJul 21, 2026
1-25 of 369376