The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-92947: Exposure of Sensitive Information to an Unauthorized Actor10.0 Critical10.0 Critical0%Sep 17, 2026
CVE-2026-92946: Improper Control of Dynamically-Managed Code Resources10.0 Critical10.0 Critical1%Sep 17, 2026
CVE-2026-92945: Improper Limitation of a Pathname to a Restricted Directory4.2 Medium2.3 Low0%Sep 17, 2026
CVE-2026-92944: Protection Mechanism Failure9.8 Critical9.3 Critical1%Sep 17, 2026
CVE-2026-92942: Uncontrolled Resource Consumption7.5 High8.7 High0%Sep 17, 2026
CVE-2026-92941: Incorrect Permission Assignment for Critical Resource10.0 Critical10.0 Critical0%Sep 17, 2026
CVE-2026-92940: Exposure of Resource to Wrong Sphere10.0 Critical10.0 Critical0%Sep 17, 2026
CVE-2026-92939: Process Control9.9 Critical9.4 Critical1%Sep 17, 2026
CVE-2026-92938: Protection Mechanism Failure9.9 Critical9.4 Critical1%Sep 17, 2026
CVE-2026-92937: Improper Control of Generation of Code10.0 Critical10.0 Critical1%Sep 17, 2026
CVE-2026-92936: Generation of Error Message Containing Sensitive Information5.8 Medium6.9 Medium0%Sep 17, 2026
CVE-2026-92935: Improper Control of Dynamically-Managed Code Resources9.0 Critical9.5 Critical1%Sep 17, 2026
CVE-2026-92934: Protection Mechanism Failure9.0 Critical9.5 Critical1%Sep 17, 2026
CVE-2026-92933: Exposure of Sensitive Information to an Unauthorized Actor5.8 Medium6.9 Medium0%Sep 17, 2026
CVE-2026-92879: Uncontrolled Resource Consumption4.3 Medium5.3 Medium1%Sep 17, 2026
CVE-2026-90986: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 17, 2026
CVE-2026-90887: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 17, 2026
CVE-2026-89418: Uncontrolled RecursionN/A8.7 High0%Sep 17, 2026
CVE-2026-86533: Insufficient Session ExpirationN/A9.1 Critical1%Sep 17, 2026
CVE-2026-86522: Improper Output Neutralization for LogsN/A6.3 Medium1%Sep 17, 2026
CVE-2026-85500: Authentication Bypass by Primary WeaknessN/A9.1 Critical1%Sep 17, 2026
CVE-2026-82761: Time-of-check Time-of-use (TOCTOU) Race ConditionN/A9.1 Critical1%Sep 17, 2026
CVE-2026-82760: Inefficient Algorithmic ComplexityN/A8.2 High1%Sep 17, 2026
CVE-2026-82759: Use of a One-Way Hash with a Predictable SaltN/A1.8 Low0%Sep 17, 2026
CVE-2026-82723: Insertion of Sensitive Information into Log FileN/A1.8 Low0%Sep 17, 2026
6526-6550 of 440896