The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-68492: Untrusted Search PathN/A8.7 High0%Sep 23, 2026
CVE-2026-68490: Incorrect Permission Assignment for Critical ResourceN/A8.2 High0%Sep 23, 2026
CVE-2026-67238: Uncontrolled Resource ConsumptionN/A7.1 High0%Sep 23, 2026
CVE-2026-66079: Allocation of Resources Without Limits or ThrottlingN/A8.2 High0%Sep 23, 2026
CVE-2026-66076: Missing AuthorizationN/A2.3 Low0%Sep 23, 2026
CVE-2026-66070: Permissive Cross-domain Policy with Untrusted DomainsN/A7.6 High0%Sep 23, 2026
CVE-2026-96872: Improper Handling of Insufficient Permissions or PrivilegesN/A2.9 Low0%Sep 23, 2026
CVE-2026-96770: Improper Following of a Certificate's Chain of TrustN/A9.3 Critical0%Sep 23, 2026
CVE-2026-96549: Cleartext Storage of Sensitive Information3.3 Low1.9 Low0%Sep 23, 2026
CVE-2026-96548: Use of Hard-coded Credentials5.6 Medium2.9 Low0%Sep 23, 2026
CVE-2026-96546: Out-of-bounds Read2.5 LowN/A0%Sep 23, 2026
CVE-2026-96545: Out-of-bounds Read4.4 MediumN/A0%Sep 23, 2026
CVE-2026-96541: Uncontrolled Resource Consumption7.5 HighN/A1%Sep 23, 2026
CVE-2026-95604: Missing Authorization7.5 HighN/A0%Sep 23, 2026
CVE-2026-95603: Deserialization of Untrusted Data7.2 HighN/A0%Sep 23, 2026
CVE-2026-95602: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Sep 23, 2026
CVE-2026-95601: Improper Neutralization of Special Elements used in an SQL Command9.3 CriticalN/A0%Sep 23, 2026
CVE-2026-95600: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Sep 23, 2026
CVE-2026-95593: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 23, 2026
CVE-2026-95592: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Sep 23, 2026
CVE-2026-95590: Improper Neutralization of Special Elements used in an SQL Command7.1 HighN/A0%Sep 23, 2026
CVE-2026-95586: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-95530: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-95529: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-95528: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
4476-4500 of 400424