The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-96680: Missing Authorization4.3 Medium2.1 Low0%Sep 23, 2026
CVE-2026-96678: Improper Limitation of a Pathname to a Restricted Directory6.3 Medium2.1 Low0%Sep 23, 2026
CVE-2026-96676: Stack-based Buffer Overflow6.3 Medium2.1 Low0%Sep 23, 2026
CVE-2026-96606: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium5.5 Medium0%Sep 23, 2026
CVE-2026-70125: Heap-based Buffer Overflow8.8 HighN/A0%Sep 23, 2026
CVE-2026-59980: Uncontrolled Resource ConsumptionN/A6.3 Medium0%Sep 23, 2026
CVE-2026-57168: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-96604: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-96603: Missing Authorization7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-96602: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-96601: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-93352: Unrestricted Upload of File with Dangerous Type9.8 Critical9.3 Critical1%Sep 23, 2026
CVE-2026-86583: Incorrect Privilege Assignment8.8 HighN/A0%Sep 23, 2026
CVE-2026-81537: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-81536: Improper Restriction of XML External Entity Reference7.7 HighN/A0%Sep 23, 2026
CVE-2026-81208: Insufficiently Protected Credentials7.7 HighN/A0%Sep 23, 2026
CVE-2026-80423: Exposure of Sensitive Information to an Unauthorized Actor8.8 HighN/A0%Sep 23, 2026
CVE-2026-75887: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Sep 23, 2026
CVE-2026-57854: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-19125: Improper Authentication8.1 HighN/A1%Sep 23, 2026
CVE-2026-96556: Improper Authorization7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-82369: Improper Neutralization of Special Elements used in an OS CommandN/A8.6 High1%Sep 23, 2026
CVE-2026-80425: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-80412: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-80379: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
4276-4300 of 742608