The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-89055: Missing Authorization9.1 CriticalN/A0%Sep 25, 2026
CVE-2026-84281: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 25, 2026
CVE-2026-84279: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 25, 2026
CVE-2026-83591: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 25, 2026
CVE-2026-78397: Server-Side Request Forgery (SSRF)4.0 MediumN/A0%Sep 25, 2026
CVE-2026-78394: Improper Limitation of a Pathname to a Restricted Directory4.1 MediumN/A0%Sep 25, 2026
CVE-2026-78393: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 25, 2026
CVE-2026-75553: Use of Hard-coded Cryptographic Key2.4 Low2.4 Low0%Sep 25, 2026
CVE-2026-62062: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 25, 2026
CVE-2026-19775: Missing Authorization4.3 MediumN/A0%Sep 25, 2026
CVE-2026-14281: Improper Privilege Management9.8 CriticalN/A1%Sep 25, 2026
CVE-2026-97721: Authorization Bypass Through User-Controlled Key2.7 Low2.0 Low0%Sep 25, 2026
CVE-2026-97818: Incorrect Authorization8.6 HighN/A0%Sep 25, 2026
CVE-2026-97764: Incorrect Behavior Order: Validate Before Canonicalize3.7 LowN/A0%Sep 25, 2026
CVE-2026-97737: Access of Resource Using Incompatible Type7.4 HighN/A0%Sep 25, 2026
CVE-2026-97736: Regular Expression without Anchors5.4 MediumN/A0%Sep 25, 2026
CVE-2026-97735: Improper Neutralization of Input During Web Page Generation8.0 HighN/A0%Sep 25, 2026
CVE-2026-97732: Improper Verification of Cryptographic Signature5.1 MediumN/A0%Sep 25, 2026
CVE-2025-14814: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 25, 2026
CVE-2026-97731: Improper Verification of Cryptographic Signature7.1 HighN/A0%Sep 25, 2026
CVE-2026-97730: Path Traversal: '../filedir'8.5 HighN/A1%Sep 25, 2026
CVE-2026-97724: Improperly Controlled Modification of Object Prototype Attributes4.3 Medium5.3 Medium0%Sep 25, 2026
CVE-2026-97650: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Sep 25, 2026
CVE-2026-97723: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 25, 2026
CVE-2026-97649: Use of Default Credentials4.7 Medium2.0 Low0%Sep 25, 2026
4976-5000 of 586239