The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-85475: Improper Neutralization of Directives in Statically Saved Code7.2 HighN/A0%Sep 23, 2026
CVE-2026-84724: Improper Neutralization of Argument Delimiters in a Command6.6 MediumN/A0%Sep 23, 2026
CVE-2026-84721: Server-Side Request Forgery (SSRF)6.4 MediumN/A0%Sep 23, 2026
CVE-2026-84720: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Sep 23, 2026
CVE-2026-84719: Missing Authorization9.9 CriticalN/A0%Sep 23, 2026
CVE-2026-84718: Use of Less Trusted Source4.3 MediumN/A0%Sep 23, 2026
CVE-2026-84717: Observable Response Discrepancy5.3 MediumN/A0%Sep 23, 2026
CVE-2026-84716: Incorrect Privilege Assignment6.6 MediumN/A0%Sep 23, 2026
CVE-2026-84714: Incomplete List of Disallowed Inputs7.1 HighN/A0%Sep 23, 2026
CVE-2026-84713: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Sep 23, 2026
CVE-2026-84712: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Sep 23, 2026
CVE-2026-84706: Incomplete List of Disallowed Inputs7.6 HighN/A0%Sep 23, 2026
CVE-2026-84691: Use of Externally-Controlled Format String8.7 HighN/A0%Sep 23, 2026
CVE-2026-84683: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Sep 23, 2026
CVE-2026-82409: Improper Encoding or Escaping of OutputN/A8.4 High0%Sep 23, 2026
CVE-2026-82407: Improper Input ValidationN/A7.0 High0%Sep 23, 2026
CVE-2026-82406: Improper Enforcement of Behavioral WorkflowN/A7.1 High0%Sep 23, 2026
CVE-2026-82405: Incorrect AuthorizationN/A8.7 High0%Sep 23, 2026
CVE-2026-75884: Incomplete List of Disallowed Inputs9.1 CriticalN/A0%Sep 23, 2026
CVE-2026-68492: Untrusted Search PathN/A8.7 High0%Sep 23, 2026
CVE-2026-68490: Incorrect Permission Assignment for Critical ResourceN/A8.2 High0%Sep 23, 2026
CVE-2026-67238: Uncontrolled Resource ConsumptionN/A7.1 High0%Sep 23, 2026
CVE-2026-66079: Allocation of Resources Without Limits or ThrottlingN/A8.2 High0%Sep 23, 2026
CVE-2026-66076: Missing AuthorizationN/A2.3 Low0%Sep 23, 2026
CVE-2026-66070: Permissive Cross-domain Policy with Untrusted DomainsN/A7.6 High0%Sep 23, 2026
4451-4475 of 398159