The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-63460: Inefficient Regular Expression Complexity7.5 HighN/A1%Sep 17, 2026
CVE-2026-63459: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Sep 17, 2026
CVE-2026-61793: Improper Input ValidationN/A6.9 Medium0%Sep 17, 2026
CVE-2026-54471: Improper Handling of Insufficient Permissions or Privileges3.5 LowN/A0%Sep 17, 2026
CVE-2026-26950: Insufficient Verification of Data Authenticity8.1 HighN/A0%Sep 17, 2026
CVE-2026-92973: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Sep 17, 2026
CVE-2026-92972: Missing Authentication for Critical Function8.6 High8.8 High0%Sep 17, 2026
CVE-2026-92971: Reachable Assertion7.5 High8.7 High1%Sep 17, 2026
CVE-2026-92970: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High1%Sep 17, 2026
CVE-2026-92963: Undefined Security Weakness5.3 Medium6.9 Medium0%Sep 17, 2026
CVE-2026-92962: Protection Mechanism FailureN/A2.1 Low0%Sep 17, 2026
CVE-2026-92961: Allocation of Resources Without Limits or Throttling7.5 High8.7 High1%Sep 17, 2026
CVE-2026-92960: Exposure of Sensitive Information to an Unauthorized Actor10.0 Critical10.0 Critical0%Sep 17, 2026
CVE-2026-92959: Protection Mechanism Failure7.1 High7.1 High0%Sep 17, 2026
CVE-2026-92958: Improper Privilege Management8.5 High8.4 High0%Sep 17, 2026
CVE-2026-92957: Improper Privilege Management9.9 Critical9.4 Critical1%Sep 17, 2026
CVE-2026-92956: Protection Mechanism Failure10.0 Critical10.0 Critical1%Sep 17, 2026
CVE-2026-92955: Improper Control of Dynamically-Managed Code Resources10.0 Critical10.0 Critical1%Sep 17, 2026
CVE-2026-92954: Uncaught Exception8.6 High9.2 Critical0%Sep 17, 2026
CVE-2026-92953: Improper Control of Dynamically-Managed Code Resources10.0 Critical9.3 Critical1%Sep 17, 2026
CVE-2026-92952: Incorrect Resource Transfer Between Spheres6.8 Medium8.9 High0%Sep 17, 2026
CVE-2026-92951: Use of Incorrectly-Resolved Name or Reference9.9 Critical9.4 Critical1%Sep 17, 2026
CVE-2026-92950: Insecure Default Variable Initialization8.6 High9.3 Critical0%Sep 17, 2026
CVE-2026-92949: Modification of Assumed-Immutable Data (MAID)4.0 Medium6.3 Medium0%Sep 17, 2026
CVE-2026-92948: Protection Mechanism Failure9.9 Critical9.4 Critical1%Sep 17, 2026
6501-6525 of 392492