The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-92628: Concurrent Execution using Shared Resource with Improper Synchronization3.1 LowN/A0%Sep 24, 2026
CVE-2026-92530: Use of Less Trusted Source4.3 MediumN/A0%Sep 24, 2026
CVE-2026-92529: Incorrect Authorization4.3 MediumN/A0%Sep 24, 2026
CVE-2026-92470: Missing Authorization7.7 HighN/A0%Sep 24, 2026
CVE-2026-89078: Double Free9.9 CriticalN/A0%Sep 24, 2026
CVE-2026-82370: Improper Neutralization of Special Elements used in a CommandN/A8.6 High1%Sep 24, 2026
CVE-2026-96680: Missing Authorization4.3 Medium2.1 Low0%Sep 23, 2026
CVE-2026-96678: Improper Limitation of a Pathname to a Restricted Directory6.3 Medium2.1 Low0%Sep 23, 2026
CVE-2026-96676: Stack-based Buffer Overflow6.3 Medium2.1 Low0%Sep 23, 2026
CVE-2026-96606: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium5.5 Medium0%Sep 23, 2026
CVE-2026-70125: Heap-based Buffer Overflow8.8 HighN/A0%Sep 23, 2026
CVE-2026-59980: Uncontrolled Resource ConsumptionN/A6.3 Medium0%Sep 23, 2026
CVE-2026-57168: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-96604: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-96603: Missing Authorization7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-96602: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-96601: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-93352: Unrestricted Upload of File with Dangerous Type9.8 Critical9.3 Critical1%Sep 23, 2026
CVE-2026-86583: Incorrect Privilege Assignment8.8 HighN/A0%Sep 23, 2026
CVE-2026-81537: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-81536: Improper Restriction of XML External Entity Reference7.7 HighN/A0%Sep 23, 2026
CVE-2026-81208: Insufficiently Protected Credentials7.7 HighN/A0%Sep 23, 2026
CVE-2026-80423: Exposure of Sensitive Information to an Unauthorized Actor8.8 HighN/A0%Sep 23, 2026
CVE-2026-75887: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Sep 23, 2026
CVE-2026-57854: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
4701-4725 of 731518