The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-66074: Inefficient Regular Expression ComplexityN/A6.0 Medium0%Sep 23, 2026
CVE-2026-66072: Uncontrolled Resource ConsumptionN/A6.0 Medium0%Sep 23, 2026
CVE-2026-66069: Missing AuthorizationN/A2.3 Low0%Sep 23, 2026
CVE-2026-66068: Insertion of Sensitive Information into Log FileN/A5.6 Medium0%Sep 23, 2026
CVE-2026-66067: Allocation of Resources Without Limits or ThrottlingN/A6.0 Medium0%Sep 23, 2026
CVE-2026-53979: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-53978: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-53969: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-53968: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-96889: Use After Free7.8 HighN/A0%Sep 23, 2026
CVE-2026-96826: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 23, 2026
CVE-2026-96552: Use of a One-Way Hash without a Salt3.1 Low1.3 Low0%Sep 23, 2026
CVE-2026-96551: Cross-Site Request Forgery (CSRF)4.3 Medium2.1 Low0%Sep 23, 2026
CVE-2026-96550: Cleartext Transmission of Sensitive Information3.7 Low2.9 Low0%Sep 23, 2026
CVE-2026-94183: User Interface (UI) Misrepresentation of Critical Information7.4 HighN/A0%Sep 23, 2026
CVE-2026-87900: Improper Neutralization of Argument Delimiters in a CommandN/A9.4 Critical1%Sep 23, 2026
CVE-2026-87899: Execution with Unnecessary PrivilegesN/A9.4 Critical1%Sep 23, 2026
CVE-2026-87898: Improper Neutralization of Special Elements used in an OS CommandN/A9.4 Critical1%Sep 23, 2026
CVE-2026-86065: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Sep 23, 2026
CVE-2026-86064: Exposure of Sensitive Information to an Unauthorized Actor8.6 HighN/A0%Sep 23, 2026
CVE-2026-85475: Improper Neutralization of Directives in Statically Saved Code7.2 HighN/A0%Sep 23, 2026
CVE-2026-84724: Improper Neutralization of Argument Delimiters in a Command6.6 MediumN/A0%Sep 23, 2026
CVE-2026-84721: Server-Side Request Forgery (SSRF)6.4 MediumN/A0%Sep 23, 2026
CVE-2026-84720: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Sep 23, 2026
CVE-2026-84719: Missing Authorization9.9 CriticalN/A0%Sep 23, 2026
4401-4425 of 838837