The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-66631: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66630: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66628: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66626: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66625: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66624: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66619: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66618: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66617: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66608: Server-Side Request Forgery (SSRF)6.4 MediumN/A0%Sep 17, 2026
CVE-2026-66580: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Sep 17, 2026
CVE-2026-66579: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66578: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66577: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66576: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66575: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Sep 17, 2026
CVE-2026-66574: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66573: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66572: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
CVE-2026-66571: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 17, 2026
CVE-2026-62108: Authentication Bypass by Spoofing9.8 CriticalN/A1%Sep 17, 2026
CVE-2026-62104: Improper Control of Generation of Code10.0 CriticalN/A1%Sep 17, 2026
CVE-2026-62101: Authentication Bypass Using an Alternate Path or Channel9.8 CriticalN/A1%Sep 17, 2026
CVE-2026-14850: Weak Password Recovery Mechanism for Forgotten PasswordN/A8.8 High0%Sep 17, 2026
CVE-2026-92954: Uncaught Exception8.6 High9.2 Critical0%Sep 17, 2026
4501-4525 of 576436