The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-81536: Improper Restriction of XML External Entity Reference7.7 HighN/A0%Sep 23, 2026
CVE-2026-81208: Insufficiently Protected Credentials7.7 HighN/A0%Sep 23, 2026
CVE-2026-80423: Exposure of Sensitive Information to an Unauthorized Actor8.8 HighN/A0%Sep 23, 2026
CVE-2026-75887: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Sep 23, 2026
CVE-2026-57854: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-19125: Improper Authentication8.1 HighN/A1%Sep 23, 2026
CVE-2026-96556: Improper Authorization7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-82369: Improper Neutralization of Special Elements used in an OS CommandN/A8.6 High1%Sep 23, 2026
CVE-2026-80425: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-80412: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-80379: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-75886: Unintended Proxy or Intermediary7.2 HighN/A0%Sep 23, 2026
CVE-2026-6935: Uncontrolled Search Path Element7.8 HighN/A0%Sep 23, 2026
CVE-2026-6928: Use After Free9.8 CriticalN/A0%Sep 23, 2026
CVE-2026-6925: Improper Limitation of a Pathname to a Restricted Directory5.3 MediumN/A0%Sep 23, 2026
CVE-2026-6794: Double Free7.8 HighN/A0%Sep 23, 2026
CVE-2026-6730: Buffer Copy without Checking Size of Input7.8 HighN/A0%Sep 23, 2026
CVE-2026-6721: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Sep 23, 2026
CVE-2026-6718: Incorrect Default Permissions6.2 MediumN/A0%Sep 23, 2026
CVE-2026-67405: Missing Origin Validation in WebSocketsN/A5.3 Medium0%Sep 23, 2026
CVE-2026-67404: Improper Certificate ValidationN/A9.2 Critical0%Sep 23, 2026
CVE-2026-67240: Inefficient Regular Expression ComplexityN/A2.3 Low0%Sep 23, 2026
CVE-2026-67235: Allocation of Resources Without Limits or ThrottlingN/A7.1 High0%Sep 23, 2026
CVE-2026-67232: Improper Handling of Highly Compressed Data (Data Amplification)N/A8.2 High0%Sep 23, 2026
CVE-2026-67231: Improper Certificate ValidationN/A9.1 Critical0%Sep 23, 2026
4301-4325 of 742608