The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-95527: Missing Authorization6.5 MediumN/A0%Sep 23, 2026
CVE-2026-95525: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Sep 23, 2026
CVE-2026-95524: Authentication Bypass by Spoofing5.3 MediumN/A0%Sep 23, 2026
CVE-2026-95523: Authentication Bypass by Spoofing6.5 MediumN/A0%Sep 23, 2026
CVE-2026-95522: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 23, 2026
CVE-2026-95515: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-95514: Authentication Bypass by Alternate Name5.3 MediumN/A0%Sep 23, 2026
CVE-2026-95513: Missing Authorization7.5 HighN/A0%Sep 23, 2026
CVE-2026-94684: Improper Neutralization of Input During Web Page GenerationN/AN/A0%Sep 23, 2026
CVE-2026-94682: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94680: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94679: Missing Authorization5.4 MediumN/A0%Sep 23, 2026
CVE-2026-94671: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94500: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94498: Missing Authorization6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94487: Cross-Site Request Forgery (CSRF)8.1 HighN/A0%Sep 23, 2026
CVE-2026-94461: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94457: Authentication Bypass by Spoofing4.8 MediumN/A0%Sep 23, 2026
CVE-2026-94391: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94181: User Interface (UI) Misrepresentation of Critical Information7.4 HighN/A0%Sep 23, 2026
CVE-2026-94179: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-94176: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-94174: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 23, 2026
CVE-2026-94168: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94124: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Sep 23, 2026
4501-4525 of 398595