The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-97650: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Sep 25, 2026
CVE-2026-97723: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 25, 2026
CVE-2026-97649: Use of Default Credentials4.7 Medium2.0 Low0%Sep 25, 2026
CVE-2026-97648: Cross-Site Request Forgery (CSRF)4.3 Medium2.1 Low0%Sep 25, 2026
CVE-2026-97647: Authorization Bypass Through User-Controlled Key5.3 Medium5.5 Medium0%Sep 25, 2026
CVE-2026-95811: Incorrect Authorization6.5 MediumN/A0%Sep 25, 2026
CVE-2026-97646: Authorization Bypass Through User-Controlled Key7.3 High5.5 Medium0%Sep 25, 2026
CVE-2026-92289: Weak Authentication9.1 CriticalN/A0%Sep 25, 2026
CVE-2026-92288: Weak Authentication9.1 CriticalN/A0%Sep 25, 2026
CVE-2026-85417: Insertion of Sensitive Information into Log FileN/A6.4 Medium0%Sep 25, 2026
CVE-2026-85082: Improper Neutralization of Special Elements used in an OS CommandN/A8.5 High0%Sep 25, 2026
CVE-2026-84283: Insecure Storage of Sensitive InformationN/A6.8 Medium0%Sep 25, 2026
CVE-2026-53493: Uncontrolled Resource ConsumptionN/A6.9 Medium0%Sep 25, 2026
CVE-2026-97387: Undefined Security WeaknessN/AN/AN/ASep 24, 2026
CVE-2026-97230: Embedded Malicious Code9.8 CriticalN/A0%Sep 24, 2026
CVE-2026-97636: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Sep 24, 2026
CVE-2026-87722: Uncontrolled Resource ConsumptionN/A8.7 High0%Sep 24, 2026
CVE-2026-87721: Uncontrolled Resource ConsumptionN/A8.7 High0%Sep 24, 2026
CVE-2026-87720: Incorrect AuthorizationN/A7.6 High0%Sep 24, 2026
CVE-2026-85491: Incomplete Comparison with Missing Factors8.8 HighN/A0%Sep 24, 2026
CVE-2026-97368: Authorization Bypass Through User-Controlled Key6.3 Medium2.1 Low0%Sep 24, 2026
CVE-2026-97366: Improper Neutralization of Special Elements used in an OS Command6.3 Medium2.1 Low1%Sep 24, 2026
CVE-2026-95699: Improper Isolation or Compartmentalization9.6 Critical8.4 High0%Sep 24, 2026
CVE-2026-93353: Improper Link Resolution Before File Access3.1 Low2.3 Low0%Sep 24, 2026
CVE-2026-88388: Stack-based Buffer Overflow7.5 HighN/A0%Sep 24, 2026
2651-2675 of 396203