The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
TitleEitWModules
CVE-2026-90457: CISA Malcolm: The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one…N/A6.9 MediumN/ASep 11, 2026
CVE-2026-90456: CISA Malcolm: An example environment-configuration file for a bundled inventory-management component ships with a fixed,…N/A9.2 CriticalN/ASep 11, 2026
CVE-2026-90455: CISA Malcolm: A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later…N/A0.0 NoneN/ASep 11, 2026
CVE-2026-90454: CISA Malcolm: A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list…N/A5.3 MediumN/ASep 11, 2026
CVE-2026-90453: CISA Malcolm: A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's…N/A5.1 MediumN/ASep 11, 2026
CVE-2026-90452: CISA Malcolm: Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential…N/A6.0 MediumN/ASep 11, 2026
CVE-2026-90451: CISA Malcolm: An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication…N/A8.2 HighN/ASep 11, 2026
CVE-2026-90450: CISA Malcolm: The application's role-authorization lookup defaults to granting access when a request handler's name is not present in…N/A5.3 MediumN/ASep 11, 2026
CVE-2026-90449: CISA Malcolm: When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party…N/A6.9 MediumN/ASep 11, 2026
CVE-2026-90448: CISA Malcolm: A deployment mode intended to expose only read access to stored data proxies a set of application programming interface…N/A7.1 HighN/ASep 11, 2026
CVE-2026-90447: CISA Malcolm: A routing rule selects between two different authentication mechanisms for the same downstream service based on the…N/A7.1 HighN/ASep 11, 2026
CVE-2026-90446: CISA Malcolm: An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path…N/A5.3 MediumN/ASep 11, 2026
CVE-2026-90445: CISA Malcolm: An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without…N/A7.1 HighN/ASep 11, 2026
CVE-2026-90444: CISA Malcolm: A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting…N/A8.7 HighN/ASep 11, 2026
CVE-2026-90443: CISA Malcolm: A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate…N/A5.3 MediumN/ASep 11, 2026
CVE-2026-90461: OpenStack Ironic: OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is…6.3 MediumN/AN/ASep 11, 2026
CVE-2026-54258: zoneminder: ZoneMinder is a free, open source closed-circuit television software application6.5 MediumN/AN/ASep 11, 2026
CVE-2026-49992: kimai: Kimai is an open-source time tracking applicationN/A6.3 MediumN/ASep 11, 2026
CVE-2026-50018: SpectoLabs hoverfly: Hoverfly is an open source API simulation tool6.5 MediumN/AN/ASep 11, 2026
CVE-2026-50013: SpectoLabs hoverfly: Hoverfly is an open source API simulation tool7.5 HighN/AN/ASep 11, 2026
CVE-2026-49846: signalwire libks: libks provides foundational support for signalwire C products7.5 HighN/AN/ASep 11, 2026
CVE-2026-54248: kimdre doco-cd: Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services…6.5 MediumN/AN/ASep 11, 2026
CVE-2026-90460: OpenStack Keystone: An issue was discovered in OpenStack Keystone before 29.0.3N/A7.6 HighN/ASep 11, 2026
CVE-2026-54241: strukturag libde265: libde265 is an open source implementation of the h.265 video codec7.4 HighN/AN/ASep 11, 2026
CVE-2026-54240: strukturag libde265: libde265 is an open source implementation of the h.265 video codec7.4 HighN/AN/ASep 11, 2026
1-25 of 390769