The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-18577:N-able N-central Authentication Bypass Exploited in the Wild
CVE-2026-66066:Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
CVE-2026-59309:Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
CVE-2026-63077:Critical unauthenticated remote code execution in JetBrains TeamCity
TitleEitWModules
CVE-2026-19353: n/a DedeCMS: A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP25.0 Medium1.3 LowN/AAug 9, 2026
CVE-2026-19352: mifi lossless-cut: A vulnerability was determined in mifi lossless-cut up to 3.69.03.1 Low1.3 LowN/AAug 9, 2026
CVE-2026-19351: dresende node-sql-query: A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.287.3 High5.5 MediumN/AAug 9, 2026
CVE-2026-19350: Dolibarr ERP: A vulnerability has been found in Dolibarr ERP up to 23.0.36.3 Medium5.3 MediumN/AAug 9, 2026
CVE-2026-19348: Shenzhen Aitemi M300 Wi-Fi Repeater: A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a9.8 Critical8.9 HighN/AAug 9, 2026
CVE-2026-19347: itsourcecode Hospital Management System: A vulnerability was identified in itsourcecode Hospital Management System 1.06.3 Medium2.1 LowN/AAug 9, 2026
CVE-2026-19346: Tenda CH22: A vulnerability was determined in Tenda CH22 1.0.0.18.8 High7.4 HighN/AAug 9, 2026
CVE-2026-19345: code-projects Task Management System: A vulnerability was found in code-projects Task Management System 1.06.5 Medium5.5 MediumN/AAug 9, 2026
CVE-2026-19344: code-projects Task Management System: A vulnerability has been found in code-projects Task Management System 1.07.3 High5.5 MediumN/AAug 9, 2026
CVE-2026-19342: code-projects Task Management System: A vulnerability was detected in code-projects Task Management System 1.07.3 High5.5 MediumN/AAug 9, 2026
CVE-2026-19343: code-projects Task Management System: A flaw has been found in code-projects Task Management System 1.07.3 High5.5 MediumN/AAug 9, 2026
CVE-2026-19341: UTT HiPER 1200GW: A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-1703068.8 High7.4 HighN/AAug 9, 2026
CVE-2026-19340: anubissbe ProjectHub-Mcp: A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.06.3 Medium2.1 LowN/AAug 9, 2026
CVE-2026-19339: aliyun alibabacloud-dataworks-mcp-server: A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.436.3 Medium2.1 LowN/AAug 9, 2026
CVE-2026-19338: automateyournetwork MCPyATS: A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.45.3 Medium1.9 LowN/AAug 9, 2026
CVE-2026-19337: adenot mcp-google-search: A vulnerability was determined in adenot mcp-google-search up to 0.3.15.3 Medium1.9 LowN/AAug 9, 2026
CVE-2026-19336: Pimzino spec-workflow-mcp: A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.65.3 Medium4.8 MediumN/AAug 9, 2026
CVE-2026-19335: Jane-xiaoer skill-vision-control: A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.05.3 Medium1.9 LowN/AAug 9, 2026
CVE-2026-18603: Unknown PiWeb Cancel order / Refund request for WooCommerce: The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or…N/AN/AN/AAug 9, 2026
CVE-2026-18473: Unknown WP Directory Kit: The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in…N/AN/AN/AAug 9, 2026
CVE-2026-18465: Unknown WP MAPS PRO: The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is…N/AN/AN/AAug 9, 2026
CVE-2026-18464: Unknown WP MAPS PRO: The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is…N/AN/AN/AAug 9, 2026
CVE-2026-18357: Unknown WPC Order Tip for WooCommerce: The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one…N/AN/AN/AAug 9, 2026
CVE-2026-18037: Unknown Create: The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of…N/AN/AN/AAug 9, 2026
CVE-2026-18032: Unknown WP Data Access: The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its…N/AN/AN/AAug 9, 2026
1-25 of 374380