The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-81445: Improper Privilege Management7.2 HighN/A0%Sep 17, 2026
CVE-2026-80356: Exposure of Sensitive Information to an Unauthorized Actor7.3 HighN/A0%Sep 17, 2026
CVE-2026-79752: Improper Neutralization of Special Elements used in an SQL CommandN/A9.2 Critical1%Sep 17, 2026
CVE-2026-77614: Session Fixation8.8 HighN/A1%Sep 17, 2026
CVE-2026-71538: Improper Neutralization of Special Elements used in an OS CommandN/A8.5 High0%Sep 17, 2026
CVE-2026-63472: Improper Authentication9.1 CriticalN/A1%Sep 17, 2026
CVE-2026-63461: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Sep 17, 2026
CVE-2026-63460: Inefficient Regular Expression Complexity7.5 HighN/A1%Sep 17, 2026
CVE-2026-63459: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Sep 17, 2026
CVE-2026-61793: Improper Input ValidationN/A6.9 Medium0%Sep 17, 2026
CVE-2026-54471: Improper Handling of Insufficient Permissions or Privileges3.5 LowN/A0%Sep 17, 2026
CVE-2026-26950: Insufficient Verification of Data Authenticity8.1 HighN/A0%Sep 17, 2026
CVE-2026-92987: Inefficient Algorithmic Complexity7.5 High8.7 High1%Sep 17, 2026
CVE-2026-92973: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Sep 17, 2026
CVE-2026-92972: Missing Authentication for Critical Function8.6 High8.8 High0%Sep 17, 2026
CVE-2026-92971: Reachable Assertion7.5 High8.7 High1%Sep 17, 2026
CVE-2026-92970: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High1%Sep 17, 2026
CVE-2026-92963: Undefined Security Weakness5.3 Medium6.9 Medium0%Sep 17, 2026
CVE-2026-92962: Protection Mechanism FailureN/A2.1 Low0%Sep 17, 2026
CVE-2026-92961: Allocation of Resources Without Limits or Throttling7.5 High8.7 High1%Sep 17, 2026
CVE-2026-92960: Exposure of Sensitive Information to an Unauthorized Actor10.0 Critical10.0 Critical0%Sep 17, 2026
CVE-2026-92959: Protection Mechanism Failure7.1 High7.1 High0%Sep 17, 2026
CVE-2026-92958: Improper Privilege Management8.5 High8.4 High0%Sep 17, 2026
CVE-2026-92957: Improper Privilege Management9.9 Critical9.4 Critical1%Sep 17, 2026
CVE-2026-92956: Protection Mechanism Failure10.0 Critical10.0 Critical1%Sep 17, 2026
4401-4425 of 576436