The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-54617: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A1%Sep 17, 2026
CVE-2026-54253: Improper Neutralization of Input During Web Page Generation8.2 HighN/A0%Sep 17, 2026
CVE-2026-54239: Insufficient Verification of Data Authenticity8.8 HighN/A0%Sep 17, 2026
CVE-2026-52851: Improper Neutralization of Special Elements used in an SQL Command7.1 HighN/A0%Sep 17, 2026
CVE-2026-54551: Improper Authorization4.3 MediumN/A0%Sep 17, 2026
CVE-2026-93295: Improper Neutralization of Special Elements in Output Used by a Downstream ComponentN/A8.7 High0%Sep 17, 2026
CVE-2026-92980: Unrestricted Upload of File with Dangerous Type7.2 High8.6 High1%Sep 17, 2026
CVE-2026-90300: Undefined Security WeaknessN/AN/A0%Sep 17, 2026
CVE-2026-90279: Undefined Security WeaknessN/AN/A0%Sep 17, 2026
CVE-2026-90110: Undefined Security Weakness9.4 CriticalN/A1%Sep 17, 2026
CVE-2026-86863: Authentication Bypass by Spoofing9.8 Critical9.3 Critical1%Sep 17, 2026
CVE-2026-81447: Improper Certificate Validation6.8 MediumN/A0%Sep 17, 2026
CVE-2026-81446: Server-Side Request Forgery (SSRF)7.4 HighN/A0%Sep 17, 2026
CVE-2026-81445: Improper Privilege Management7.2 HighN/A0%Sep 17, 2026
CVE-2026-80356: Exposure of Sensitive Information to an Unauthorized Actor7.3 HighN/A0%Sep 17, 2026
CVE-2026-77614: Session Fixation8.8 HighN/A1%Sep 17, 2026
CVE-2026-63459: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Sep 17, 2026
CVE-2026-81453: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Sep 17, 2026
CVE-2026-81443: Server-Side Request Forgery (SSRF)6.4 MediumN/A0%Sep 17, 2026
CVE-2026-81442: Improper Privilege Management8.1 HighN/A0%Sep 17, 2026
CVE-2026-80355: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Sep 17, 2026
CVE-2026-66631: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66630: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66625: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
CVE-2026-66624: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 17, 2026
576-600 of 17379