The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-107225: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets6.5 MediumN/AN/AOct 7, 2026
CVE-2026-107224: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets6.5 MediumN/AN/AOct 7, 2026
CVE-2026-107223: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheetsN/A7.1 HighN/AOct 7, 2026
CVE-2026-103371: Apache Software Foundation Apache Geode: Insertion of Sensitive Information into Log File in Apache Geode Web ManagementN/AN/AN/AOct 7, 2026
CVE-2026-107222: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets6.5 MediumN/AN/AOct 7, 2026
CVE-2026-107221: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets6.5 MediumN/AN/AOct 7, 2026
CVE-2026-107220: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets6.5 MediumN/AN/AOct 7, 2026
CVE-2026-107219: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets7.5 HighN/AN/AOct 7, 2026
CVE-2026-107218: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets5.3 MediumN/AN/AOct 7, 2026
CVE-2026-107217: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets7.5 HighN/AN/AOct 7, 2026
CVE-2026-107313: pgjdbc: pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 and 42.7.5 can send the previous contents of the GSS send buffer in…4.2 MediumN/AN/AOct 7, 2026
CVE-2026-96335: WPMU DEV Forminator: Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control…7.5 HighN/AN/AOct 7, 2026
CVE-2026-56851: golang.org/x/text golang.org/x/text/secure/precis: The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short…N/AN/AN/AOct 7, 2026
CVE-2026-107215: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets7.5 HighN/AN/AOct 7, 2026
CVE-2026-107214: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets7.5 HighN/AN/AOct 7, 2026
CVE-2026-107213: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheetsN/A8.7 HighN/AOct 7, 2026
CVE-2026-107212: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets7.5 HighN/AN/AOct 7, 2026
CVE-2026-107211: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheetsN/A8.7 HighN/AOct 7, 2026
CVE-2026-106066: Red Hat: A heap-based buffer overflow was found in GIMP’s raw data export plug-in6.3 MediumN/AN/AOct 7, 2026
CVE-2026-106164: Progress Software Telerik Document Processing Libraries: In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop…7.3 HighN/AN/AOct 7, 2026
CVE-2026-107216: qax-os excelize: Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets7.5 HighN/AN/AOct 7, 2026
CVE-2026-106067: Red Hat: A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in6.3 MediumN/AN/AOct 7, 2026
CVE-2026-95606: Liquid Web / StellarWP The Events Calendar: Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection9.8 CriticalN/AN/AOct 7, 2026
CVE-2026-95595: Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin…7.1 HighN/AN/AOct 7, 2026
CVE-2026-95534: Unlimited Elements: Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets,…8.8 HighN/AN/AOct 7, 2026
1-25 of 399818
›