The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-100716: Improper Link Resolution Before File Access9.9 Critical9.4 Critical0%Sep 26, 2026
CVE-2026-100714: Improper Neutralization of Argument Delimiters in a Command9.1 Critical9.4 Critical1%Sep 26, 2026
CVE-2026-100709: Improper Authentication7.5 High7.7 High0%Sep 26, 2026
CVE-2026-100673: Improper Neutralization of Input During Web Page Generation8.2 High8.4 High0%Sep 26, 2026
CVE-2026-100671: Exposure of Sensitive Information to an Unauthorized Actor8.0 High8.6 High0%Sep 26, 2026
CVE-2026-100646: Origin Validation Error8.1 High8.6 High0%Sep 26, 2026
CVE-2026-100642: Origin Validation Error7.6 High7.2 High0%Sep 26, 2026
CVE-2026-100641: Improper Neutralization of Input During Web Page Generation8.0 High8.6 High1%Sep 26, 2026
CVE-2026-100638: External Control of File Name or Path7.6 High8.3 High0%Sep 26, 2026
CVE-2026-100637: External Control of File Name or Path7.6 High8.3 High0%Sep 26, 2026
CVE-2026-100636: Improper Limitation of a Pathname to a Restricted Directory7.6 High8.3 High1%Sep 26, 2026
CVE-2026-100633: Incorrect Authorization6.5 Medium8.5 High0%Sep 26, 2026
CVE-2026-100630: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Sep 26, 2026
CVE-2026-100629: Incorrect Authorization5.5 Medium7.0 High0%Sep 26, 2026
CVE-2026-96531: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Sep 26, 2026
CVE-2026-96525: Missing Authorization2.7 LowN/A0%Sep 26, 2026
CVE-2026-96524: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 26, 2026
CVE-2026-85081: Improper Neutralization of Input During Web Page Generation7.5 HighN/A0%Sep 26, 2026
CVE-2026-11871: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Sep 26, 2026
CVE-2026-15273: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 26, 2026
CVE-2026-100588: Incorrect Authorization8.3 High8.7 High0%Sep 26, 2026
CVE-2026-100579: Authorization Bypass Through User-Controlled Key7.6 High7.2 High0%Sep 26, 2026
CVE-2026-100578: Improper Privilege Management7.6 High7.2 High0%Sep 26, 2026
CVE-2026-100562: Incorrect Authorization5.4 Medium5.3 Medium0%Sep 26, 2026
CVE-2026-100550: Incorrect Authorization5.4 Medium5.3 Medium0%Sep 26, 2026
276-300 of 17400