The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
TitleEitWModules
CVE-2026-84888: RightNow-AI OpenFang: A weakness has been identified in RightNow-AI OpenFang up to 0.6.94.3 Medium2.1 LowN/ASep 3, 2026
CVE-2026-84887: simular-ai Agent-S: A vulnerability was identified in simular-ai Agent-S up to 0.3.24.3 Medium2.1 LowN/ASep 3, 2026
CVE-2026-84886: simular-ai Agent-S: A vulnerability was determined in simular-ai Agent-S up to 0.3.25.3 Medium5.5 MediumN/ASep 3, 2026
CVE-2026-84885: simular-ai Agent-S: A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.24.3 Medium2.1 LowN/ASep 3, 2026
CVE-2026-84851: Amazon ion-c: An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated…7.5 High8.7 HighN/ASep 3, 2026
CVE-2026-84394: fast-uri: fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error7.5 HighN/AN/ASep 3, 2026
CVE-2026-66049: Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.N/AN/AN/ASep 3, 2026
CVE-2026-66048: Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.N/AN/AN/ASep 3, 2026
CVE-2026-2573: ataurr: The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is…6.4 MediumN/AN/ASep 3, 2026
CVE-2026-85040: ZhongBangKeJi CRMEB: A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.04.7 Medium5.1 MediumN/ASep 3, 2026
CVE-2021-38489: Insyde Software InsydeH2O: HDD password plaintext is stored in a UEFI variable.8.2 HighN/AN/ASep 3, 2026
CVE-2021-43614: Insyde Software InsydeH2O: Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and…6.7 MediumN/AN/ASep 3, 2026
CVE-2021-43613: Insyde Software InsydeH2O: An issue was discovered in SysPasswordDxe in Insyde InsydeH2O6.5 MediumN/AN/ASep 3, 2026
CVE-2026-85031: TOTOLINK CP450: A vulnerability was found in TOTOLINK CP450 4.1.09.9 Critical9.4 CriticalN/ASep 3, 2026
CVE-2026-85030: HKUDS AI-Trader: A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df3.7 Low6.3 MediumN/ASep 3, 2026
CVE-2026-85093: cheshire-cat-ai core: Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when…6.5 Medium7.1 HighN/ASep 3, 2026
CVE-2026-85092: jtsylve LiME: LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the…6.6 Medium5.2 MediumN/ASep 3, 2026
CVE-2026-85091: zlib: zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when…7.4 High8.3 HighN/ASep 3, 2026
CVE-2026-85090: FreeRDP: FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during…5.4 Medium5.3 MediumN/ASep 3, 2026
CVE-2026-85089: FreeRDP: FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU…6.5 Medium7.1 HighN/ASep 3, 2026
CVE-2026-85022: langgenius dify: A vulnerability was identified in langgenius dify 1.13.03.5 Low5.1 MediumN/ASep 3, 2026
CVE-2026-85021: langgenius dify: A vulnerability was determined in langgenius dify 1.13.04.3 Medium5.3 MediumN/ASep 3, 2026
CVE-2026-85084: Samsung Open Source TizenFX: Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX…6.3 MediumN/AN/ASep 2, 2026
CVE-2026-84857: sigoden aichat: A flaw has been found in sigoden aichat up to 0.30.45.3 Medium5.5 MediumN/ASep 2, 2026
CVE-2026-84856: rowboatlabs rowboat: A vulnerability was detected in rowboatlabs rowboat up to 0.9.15.3 Medium5.5 MediumN/ASep 2, 2026
1-25 of 391960