The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
TitleEitWModules
CVE-2026-85702: ramon-victor freegpt-webui: A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc7.3 High6.9 MediumN/ASep 4, 2026
CVE-2026-85786: Amazon ion-java: Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a…7.5 High8.7 HighN/ASep 4, 2026
CVE-2026-85643: code-projects Online Shopping System: A flaw has been found in code-projects Online Shopping System 1.04.7 Medium2.0 LowN/ASep 4, 2026
CVE-2026-79391: n/a: No authentication exists in the MQTT service of Trueview 6.0.23.4N/AN/AN/ASep 4, 2026
CVE-2026-79390: n/a: Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in…N/AN/AN/ASep 4, 2026
CVE-2026-79389: n/a: Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processingN/AN/AN/ASep 4, 2026
CVE-2026-71626: n/a: An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the…N/AN/AN/ASep 4, 2026
CVE-2026-71625: n/a: An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the…N/AN/AN/ASep 4, 2026
CVE-2026-71624: n/a: An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the…N/AN/AN/ASep 4, 2026
CVE-2026-71622: n/a: SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information…N/AN/AN/ASep 4, 2026
CVE-2026-63464: forgekeep nebula-mesh: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN7.7 HighN/AN/ASep 4, 2026
CVE-2026-61699: forgekeep nebula-mesh: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN8.1 HighN/AN/ASep 4, 2026
CVE-2026-55513: forgekeep nebula-mesh: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN5.4 MediumN/AN/ASep 4, 2026
CVE-2026-55512: forgekeep nebula-mesh: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN5.3 MediumN/AN/ASep 4, 2026
CVE-2026-53932: stefanzweifel laravel-backup-restore: laravel-backup-restore restores database backups made with spatie/laravel-backup8.0 HighN/AN/ASep 4, 2026
CVE-2026-53604: forgekeep nebula-mesh: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPNN/A7.1 HighN/ASep 4, 2026
CVE-2026-53603: forgekeep nebula-mesh: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPNN/A7.1 HighN/ASep 4, 2026
CVE-2026-53602: forgekeep nebula-mesh: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPNN/A6.9 MediumN/ASep 4, 2026
CVE-2026-85701: ramon-victor freegpt-webui: A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc5.3 Medium6.9 MediumN/ASep 4, 2026
CVE-2026-85787: Amazon postgres-mcp-server: An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before…6.5 Medium7.1 HighN/ASep 4, 2026
CVE-2026-53769: avo-hq avo: Avo is a framework to create admin panels for Ruby on Rails apps6.5 MediumN/AN/ASep 4, 2026
CVE-2026-85781: aws aws-efs-csi-driver: Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before…8.7 High5.1 MediumN/ASep 4, 2026
CVE-2026-85639: jofpin trape: A security vulnerability has been detected in jofpin trape 2.05.6 Medium2.9 LowN/ASep 4, 2026
CVE-2026-85638: jofpin trape: A weakness has been identified in jofpin trape 2.07.3 High5.5 MediumN/ASep 4, 2026
CVE-2026-85637: jofpin trape: A security flaw has been discovered in jofpin trape 1.0.0/2.05.3 Medium5.5 MediumN/ASep 4, 2026
1-25 of 389174