The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63520:Microsoft SharePoint Remote Code Execution (FIXED)
TitleEitWModules
CVE-2026-76177: OCS Inventory NG Ocsreports: Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to…N/A7.1 HighN/ASep 3, 2026
CVE-2026-76176: OCS Inventory NG Ocsreports: SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of…N/A8.6 HighN/ASep 3, 2026
CVE-2026-85100: 2FastLabs agent-squad: A vulnerability was detected in 2FastLabs agent-squad up to 1.1.44.3 Medium5.3 MediumN/ASep 3, 2026
CVE-2026-76175: OCS Inventory NG Ocsreports: SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpointN/A8.6 HighN/ASep 3, 2026
CVE-2026-76174: OCS Inventory NG Ocsreports: Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpointN/A9.4 CriticalN/ASep 3, 2026
CVE-2026-80253: Shizen Connect Inc. ShizenBox2 (dev-conf): An improper physical access control issue exists in ShizenBox2 (dev-conf)6.8 Medium7.0 HighN/ASep 3, 2026
CVE-2026-80254: Shizen Connect Inc. ShizenBox2 (edge-app): Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app)6.5 Medium7.1 HighN/ASep 3, 2026
CVE-2026-84830: SEPPmail AG Secure Email Gateway: SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated…N/A8.6 HighN/ASep 3, 2026
CVE-2026-84832: SEPPmail AG SEPPmail Secure Email Gateway (SEG): SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow…N/A8.6 HighN/ASep 3, 2026
CVE-2026-84831: SEPPmail AG SEPPmail Secure Email Gateway (SEG): SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor…N/A7.7 HighN/ASep 3, 2026
CVE-2026-3852: Elegant Themes Divi: The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of…6.4 MediumN/AN/ASep 3, 2026
CVE-2026-80757: Linux: In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its…N/AN/AN/ASep 3, 2026
CVE-2026-80756: Linux: In the Linux kernel, the following vulnerability has been resolved: selinux: do not cancel a policy conversion that…N/AN/AN/ASep 3, 2026
CVE-2026-80755: Linux: In the Linux kernel, the following vulnerability has been resolved: selinux: reject a permission value exceeding the…N/AN/AN/ASep 3, 2026
CVE-2026-80754: Linux: In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55 transmitter…N/AN/AN/ASep 3, 2026
CVE-2026-80753: Linux: In the Linux kernel, the following vulnerability has been resolved: ovpn: run deferred work on a module-owned workqueue…N/AN/AN/ASep 3, 2026
CVE-2026-80752: Linux: In the Linux kernel, the following vulnerability has been resolved: Input: psxpad-spi - set driver data before use…N/AN/AN/ASep 3, 2026
CVE-2026-80751: Linux: In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: mfg: initialize prev_o in…N/AN/AN/ASep 3, 2026
CVE-2026-80750: Linux: In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix remaining %pOF after…N/AN/AN/ASep 3, 2026
CVE-2026-80749: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/connector/hdmi: Fix out of bounds memory read A…N/AN/AN/ASep 3, 2026
CVE-2026-80748: Linux: In the Linux kernel, the following vulnerability has been resolved: mmc: loongson2: Fix sg iteration in data reorder…N/AN/AN/ASep 3, 2026
CVE-2026-80747: Linux: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check for CRAT subtype…N/AN/AN/ASep 3, 2026
CVE-2026-80746: Linux: In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-eliza: Fix…N/AN/AN/ASep 3, 2026
CVE-2026-80745: Linux: In the Linux kernel, the following vulnerability has been resolved: regulator: fp9931: Fix VPOS/VNEG voltage selector…N/AN/AN/ASep 3, 2026
CVE-2026-80744: Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables_offload: suppress WARN_ON_ONCE…N/AN/AN/ASep 3, 2026
1-25 of 379180