The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-13355: Improper Privilege Management9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-93340: Weak Password Recovery Mechanism for Forgotten Password6.8 Medium7.4 High0%Sep 21, 2026
CVE-2026-88738: Unrestricted Upload of File with Dangerous Type8.8 HighN/A0%Sep 21, 2026
CVE-2026-59814: Improper Neutralization of Input During Web Page Generation7.6 HighN/A0%Sep 21, 2026
CVE-2026-79317: Insufficient Session Expiration4.8 MediumN/A0%Sep 21, 2026
CVE-2026-59816: Improper Limitation of a Pathname to a Restricted Directory4.3 MediumN/A0%Sep 21, 2026
CVE-2026-52835: Improper Limitation of a Pathname to a Restricted DirectoryN/A7.0 High1%Sep 21, 2026
CVE-2026-49995: Improper Neutralization of Input During Web Page GenerationN/A4.8 Medium1%Sep 21, 2026
CVE-2026-94412: Missing Authorization8.8 High8.7 High0%Sep 21, 2026
CVE-2026-94411: Missing Authorization8.8 High8.7 High0%Sep 21, 2026
CVE-2026-91167: Missing AuthorizationN/A6.0 Medium0%Sep 21, 2026
CVE-2026-63330: Improper Authorization7.7 HighN/A0%Sep 21, 2026
CVE-2026-58491: Improper Neutralization of Input During Web Page Generation9.3 CriticalN/A0%Sep 21, 2026
CVE-2026-84990: Exposure of Sensitive Information to an Unauthorized Actor8.8 HighN/A0%Sep 21, 2026
CVE-2026-83621: Missing Authorization8.1 HighN/A0%Sep 21, 2026
CVE-2026-79920: Missing Authorization9.9 CriticalN/A0%Sep 21, 2026
CVE-2026-63416: Improper Limitation of a Pathname to a Restricted Directory3.7 LowN/A0%Sep 21, 2026
CVE-2026-17050: Double Free5.7 MediumN/A0%Sep 21, 2026
CVE-2026-82412: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A0%Sep 21, 2026
CVE-2026-80110: Incorrect Authorization8.1 HighN/A0%Sep 21, 2026
CVE-2026-61628: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A0%Sep 21, 2026
CVE-2026-55870: Exposure of Sensitive Information to an Unauthorized ActorN/A2.3 Low1%Sep 21, 2026
CVE-2026-55625: Authorization Bypass Through User-Controlled Key4.9 MediumN/A1%Sep 21, 2026
CVE-2026-55060: Incorrect Authorization3.7 LowN/A0%Sep 21, 2026
CVE-2026-52742: Incorrect AuthorizationN/A5.1 Medium1%Sep 21, 2026
476-500 of 17396