The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-102877: Server-Side Request Forgery (SSRF)4.4 Medium2.1 Low0%Sep 29, 2026
CVE-2026-100296: Improper Check for Unusual or Exceptional Conditions8.1 High7.2 High0%Sep 29, 2026
CVE-2026-102425: Improper Control of Generation of Code10.0 Critical9.5 Critical0%Sep 29, 2026
CVE-2026-101127: Improper Neutralization of Input During Web Page Generation9.4 Critical8.6 High0%Sep 29, 2026
CVE-2026-54872: Observable Timing Discrepancy3.7 LowN/A0%Sep 29, 2026
CVE-2026-102630: Use of Less Trusted Source4.7 Medium2.3 Low0%Sep 29, 2026
CVE-2026-102601: Improper Neutralization of Escape, Meta, or Control Sequences3.5 LowN/A0%Sep 29, 2026
CVE-2026-100286: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Sep 29, 2026
CVE-2026-49243: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Sep 29, 2026
CVE-2026-102570: Improper Neutralization of Special Elements used in an SQL Command5.5 Medium7.0 High0%Sep 29, 2026
CVE-2026-102569: Improper Neutralization of Special Elements used in an SQL Command5.5 Medium7.0 High0%Sep 29, 2026
CVE-2026-4034: Improper Neutralization of Special Elements in Output Used by a Downstream ComponentN/A8.7 High0%Sep 29, 2026
CVE-2026-102366: Unrestricted Upload of File with Dangerous Type4.4 Medium2.1 Low0%Sep 29, 2026
CVE-2026-102335: Incorrect Authorization7.1 High7.1 High0%Sep 28, 2026
CVE-2026-102334: Improper Restriction of Excessive Authentication Attempts7.4 High9.1 Critical0%Sep 28, 2026
CVE-2026-101093: Cross-Site Request Forgery (CSRF)5.4 Medium5.3 Medium0%Sep 28, 2026
CVE-2026-91095: Use After Free5.3 MediumN/A0%Sep 28, 2026
CVE-2026-100392: Incorrect AuthorizationN/A7.0 High0%Sep 28, 2026
CVE-2026-100371: Incorrect AuthorizationN/A8.7 High0%Sep 28, 2026
CVE-2026-93355: Weak Authentication8.1 High7.6 High0%Sep 28, 2026
CVE-2026-54674: Improper Neutralization of Special Elements used in an OS CommandN/A8.6 High1%Sep 28, 2026
CVE-2026-45562: Improper Neutralization of Special Elements used in an OS CommandN/A7.7 High0%Sep 28, 2026
CVE-2026-87969: Improper Neutralization of Special Elements used in an OS CommandN/A8.6 High1%Sep 28, 2026
CVE-2026-54160: Inclusion of Functionality from Untrusted Control Sphere8.2 HighN/A0%Sep 28, 2026
CVE-2026-101081: Stack-based Buffer Overflow9.1 Critical8.5 High1%Sep 28, 2026
226-250 of 17409