The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-59309:Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
TitleEitWModules
CVE-2026-58039: nodejs node: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside…3.3 LowN/AN/AJul 31, 2026
CVE-2026-66421: tugcantopaloglu openclaw-dashboard: OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to…9.3 Critical8.8 HighN/AJul 30, 2026
CVE-2026-66420: tugcantopaloglu openclaw-dashboard: MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows…8.8 High8.6 HighN/AJul 30, 2026
CVE-2026-66364: MZ Automation GmbH libiec61850: The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2…6.5 Medium7.1 HighN/AJul 30, 2026
CVE-2026-66360: MZ Automation GmbH libiec61850: The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation7.5 High8.7 HighN/AJul 30, 2026
CVE-2026-66349: MZ Automation GmbH libiec61850: The MMS server connection handler contains a flaw in its processing of BER-encoded request data6.5 Medium6.9 MediumN/AJul 30, 2026
CVE-2026-65423: o6 Automation open62541: An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to…8.8 High8.7 HighN/AJul 30, 2026
CVE-2026-65421: MZ Automation GmbH libiec61850: The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length…6.5 Medium7.1 HighN/AJul 30, 2026
CVE-2026-63362: o6 Automation open62541: An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to…5.9 Medium8.2 HighN/AJul 30, 2026
CVE-2026-63035: o6 Automation open62541: A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated…8.1 High7.2 HighN/AJul 30, 2026
CVE-2026-56758: MZ Automation GmbH libiec61850: The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment6.5 Medium6.9 MediumN/AJul 30, 2026
CVE-2026-61893: MZ Automation lib60870: A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes…6.5 Medium6.9 MediumN/AJul 30, 2026
CVE-2026-63033: MZ Automation lib60870: A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes…6.5 Medium6.9 MediumN/AJul 30, 2026
CVE-2026-10031: drakkan SFTPGo: SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent…4.2 Medium2.3 LowN/AJul 30, 2026
CVE-2026-66720: MZ Automation GmbH libiec61850: The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE…6.5 Medium7.1 HighN/AJul 30, 2026
CVE-2026-66369: MZ Automation GmbH libiec61850: The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated…6.5 Medium7.1 HighN/AJul 30, 2026
CVE-2026-63550: MZ Automation GmbH libiec61850: The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request…6.5 Medium7.1 HighN/AJul 30, 2026
CVE-2026-68563: Red Hat: A flaw was found in ansible-collection-redhat-leapp5.5 MediumN/AN/AJul 30, 2026
CVE-2026-68562: Red Hat: A flaw was found in ansible-collection-redhat-leapp6.2 MediumN/AN/AJul 30, 2026
CVE-2026-64816: CyberTimon RapidRAW: RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in…6.5 Medium7.1 HighN/AJul 30, 2026
CVE-2026-63559: o6 Automation open62541: An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to…7.5 High8.7 HighN/AJul 30, 2026
CVE-2026-62845: clastix kamaji: Kamaji is the Hosted Control Plane Manager for Kubernetes4.7 MediumN/AN/AJul 30, 2026
CVE-2026-62246: clastix kamaji: Kamaji is the Hosted Control Plane Manager for Kubernetes8.5 HighN/AN/AJul 30, 2026
CVE-2026-5846: Watchfire: The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509…5.7 Medium7.6 HighN/AJul 30, 2026
CVE-2026-38709: n/a: TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600…N/AN/AN/AJul 30, 2026
1-25 of 372088