The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-87739: PaperCut PaperCut NG/MF: An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report…N/A6.9 MediumN/ASep 24, 2026
CVE-2026-82077: PaperCut PaperCut NG/MF: An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax…N/A7.3 HighN/ASep 24, 2026
CVE-2026-81645: Huawei HarmonyOS: Out-of-bounds read vulnerability in the graphics module5.9 MediumN/AN/ASep 24, 2026
CVE-2026-11744: PaperCut PaperCut Hive: An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devicesN/A3.8 LowN/ASep 24, 2026
CVE-2026-97181: ezGlobal GPM LIGHT: GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability5.3 Medium6.9 MediumN/ASep 24, 2026
CVE-2026-97177: Red Hat: A flaw was found in the user update mechanism of the Keycloak Admin REST API6.6 MediumN/AN/ASep 24, 2026
CVE-2026-97176: Red Hat: A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management…4.2 MediumN/AN/ASep 24, 2026
CVE-2026-97168: Rejected reason: suggestionN/AN/AN/ASep 24, 2026
CVE-2026-93662: Unknown Events Manager: The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search…N/AN/AN/ASep 24, 2026
CVE-2026-93661: Unknown Events Manager: The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers…N/AN/AN/ASep 24, 2026
CVE-2026-89005: Unknown WPeMatico RSS Feed Fetcher: The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign…N/AN/AN/ASep 24, 2026
CVE-2026-89004: Unknown WPeMatico RSS Feed Fetcher: The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before…N/AN/AN/ASep 24, 2026
CVE-2026-89002: Unknown WPeMatico RSS Feed Fetcher: The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a…N/AN/AN/ASep 24, 2026
CVE-2026-88847: Unknown MasterStudy LMS WordPress Plugin: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course…N/AN/AN/ASep 24, 2026
CVE-2026-88846: Unknown MasterStudy LMS WordPress Plugin: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled…N/AN/AN/ASep 24, 2026
CVE-2026-88845: Unknown MasterStudy LMS WordPress Plugin: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on…N/AN/AN/ASep 24, 2026
CVE-2026-88843: Unknown MasterStudy LMS WordPress Plugin: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings…N/AN/AN/ASep 24, 2026
CVE-2026-84151: Unknown The Post Grid: The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own…N/AN/AN/ASep 24, 2026
CVE-2026-82850: Unknown Masteriyo LMS: The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any…N/AN/AN/ASep 24, 2026
CVE-2026-82849: Unknown Masteriyo LMS: The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the…N/AN/AN/ASep 24, 2026
CVE-2026-82195: Unknown 10Web Booster: The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret…N/AN/AN/ASep 24, 2026
CVE-2026-80513: Unknown wpForo Forum: The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes…N/AN/AN/ASep 24, 2026
CVE-2026-80338: Unknown CMB2: The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing…N/AN/AN/ASep 24, 2026
CVE-2026-74991: Unknown WPForms: The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form…N/AN/AN/ASep 24, 2026
CVE-2026-14780: PaperCut PaperCut NG/MF: A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization…N/A7.5 HighN/ASep 24, 2026
1-25 of 559420