The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
CVE-2026-50751:Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
TitleEitWModules
CVE-2026-16270: Open Mercato: Open Mercato does not validate regex rulesN/A6.9 MediumN/AJul 22, 2026
CVE-2026-8152: Unblu inc. Unblu Spark: Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS)…N/A7.0 HighN/AJul 22, 2026
CVE-2026-65603: getgrav grav: The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated…8.8 High8.7 HighN/AJul 22, 2026
CVE-2026-65602: traefik: Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for…N/A5.3 MediumN/AJul 22, 2026
CVE-2026-65601: traefik: Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API providerN/A5.3 MediumN/AJul 22, 2026
CVE-2026-65600: traefik: Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path…N/A7.8 HighN/AJul 22, 2026
CVE-2026-65599: n8n-io n8n: n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a…N/A5.1 MediumN/AJul 22, 2026
CVE-2026-65597: n8n-io n8n: n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in…N/A8.2 HighN/AJul 22, 2026
CVE-2026-65596: n8n-io n8n: n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based…N/A5.1 MediumN/AJul 22, 2026
CVE-2026-65595: n8n-io n8n: n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module…N/A8.9 HighN/AJul 22, 2026
CVE-2026-65594: n8n-io n8n: n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow…N/A5.1 MediumN/AJul 22, 2026
CVE-2026-65593: n8n-io n8n: n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters…N/A6.3 MediumN/AJul 22, 2026
CVE-2026-65591: n8n-io n8n: n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handlerN/A8.9 HighN/AJul 22, 2026
CVE-2026-65590: n8n-io n8n: n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the…N/A5.5 MediumN/AJul 22, 2026
CVE-2026-65589: n8n-io n8n: n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data,…N/A5.1 MediumN/AJul 22, 2026
CVE-2026-65016: n8n-io n8n: n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO…N/A7.7 HighN/AJul 22, 2026
CVE-2026-65015: n8n-io n8n: n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the…N/A7.2 HighN/AJul 22, 2026
CVE-2026-44192: Red Hat Red Hat Ansible Automation Platform 2: A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server6.6 MediumN/AN/AJul 22, 2026
CVE-2026-44190: Red Hat Red Hat Ansible Automation Platform 2: A flaw was found in the Ansible Lightspeed Visual Studio Code extension7.8 HighN/AN/AJul 22, 2026
CVE-2026-44187: Red Hat Red Hat Ansible Automation Platform 2: A flaw was found in the Ansible Lightspeed extension for Visual Studio Code3.3 LowN/AN/AJul 22, 2026
CVE-2026-16544: Red Hat Red Hat Ansible Automation Platform 2: A flaw was found in AWX6.5 MediumN/AN/AJul 22, 2026
CVE-2026-44191: Red Hat Red Hat Ansible Automation Platform 2: A flaw was found in the Visual Studio Code Ansible Lightspeed extension7.8 HighN/AN/AJul 22, 2026
CVE-2026-4773: Magarsus Consulting Ltd. Co. IDM-MFA: Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd8.1 HighN/AN/AJul 22, 2026
CVE-2026-44189: Red Hat Red Hat Ansible Automation Platform 2: A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider7.8 HighN/AN/AJul 22, 2026
CVE-2025-13146: sevenspark Contact Form 7 – Dynamic Text Extension: The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in…6.5 MediumN/AN/AJul 22, 2026
1-25 of 369410