The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-86330: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A2%Sep 28, 2026
CVE-2026-90979: Improper Neutralization of Special Elements used in an LDAP Query7.3 HighN/A0%Sep 28, 2026
CVE-2026-7172: Improper Neutralization of Input During Web Page GenerationN/A4.8 Medium0%Sep 28, 2026
CVE-2026-7171: Improper Neutralization of Input During Web Page GenerationN/A4.8 Medium0%Sep 28, 2026
CVE-2026-7170: Improper Neutralization of Input During Web Page GenerationN/A4.8 Medium0%Sep 28, 2026
CVE-2026-86530: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High0%Sep 28, 2026
CVE-2026-86507: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 28, 2026
CVE-2026-82386: Improper Restriction of XML External Entity Reference7.7 HighN/A0%Sep 28, 2026
CVE-2026-82385: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Sep 28, 2026
CVE-2026-82383: Missing Authentication for Critical Function8.2 HighN/A0%Sep 28, 2026
CVE-2026-82381: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 28, 2026
CVE-2026-82380: Cross-Site Request Forgery (CSRF)8.1 HighN/A0%Sep 28, 2026
CVE-2026-82379: Authentication Bypass by Capture-replay7.7 HighN/A0%Sep 28, 2026
CVE-2026-82378: Incorrect Authorization9.0 CriticalN/A0%Sep 28, 2026
CVE-2026-82348: Authorization Bypass Through User-Controlled Key7.7 HighN/A0%Sep 28, 2026
CVE-2026-101085: Numeric Truncation Error6.5 Medium7.1 High0%Sep 27, 2026
CVE-2026-101065: Missing Authentication for Critical Function9.8 Critical9.3 Critical0%Sep 27, 2026
CVE-2026-101048: Incorrect Authorization5.4 Medium5.3 Medium0%Sep 27, 2026
CVE-2026-100871: Improper Authentication8.8 High8.7 High0%Sep 27, 2026
CVE-2026-100870: Weak Password Recovery Mechanism for Forgotten Password8.8 High8.7 High0%Sep 27, 2026
CVE-2026-93304: Incorrect Behavior Order3.7 Low6.3 Medium0%Sep 27, 2026
CVE-2026-97227: Missing Authorization5.9 MediumN/A0%Sep 27, 2026
CVE-2026-96896: Missing Authorization7.2 HighN/A0%Sep 27, 2026
CVE-2026-89001: Improper Privilege Management4.9 MediumN/A0%Sep 27, 2026
CVE-2026-86841: Deserialization of Untrusted Data4.7 MediumN/A0%Sep 27, 2026
251-275 of 17408