The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-90050: Undefined Security WeaknessN/AN/A0%Sep 17, 2026
CVE-2026-8674: Reachable Assertion5.3 MediumN/A0%Sep 17, 2026
CVE-2026-85720: Cleartext Transmission of Sensitive Information5.9 MediumN/A0%Sep 17, 2026
CVE-2026-85716: Improper Authentication3.7 LowN/A0%Sep 17, 2026
CVE-2026-54587: Improper Link Resolution Before File AccessN/A5.8 Medium0%Sep 17, 2026
CVE-2026-54586: Cleartext Transmission of Sensitive InformationN/A6.0 Medium0%Sep 17, 2026
CVE-2026-54585: Improper Limitation of a Pathname to a Restricted DirectoryN/A6.0 Medium1%Sep 17, 2026
CVE-2026-54583: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.3 High1%Sep 17, 2026
CVE-2026-54582: External Control of File Name or PathN/A6.0 Medium1%Sep 17, 2026
CVE-2026-54581: Insufficient Verification of Data AuthenticityN/A8.3 High0%Sep 17, 2026
CVE-2026-54580: Improper Validation of Integrity Check ValueN/A8.3 High0%Sep 17, 2026
CVE-2026-54579: Out-of-bounds ReadN/A2.3 Low0%Sep 17, 2026
CVE-2026-54578: Improper Validation of Integrity Check ValueN/A2.0 Low0%Sep 17, 2026
CVE-2026-54577: Improper Input ValidationN/A2.0 Low0%Sep 17, 2026
CVE-2026-54576: Improper Link Resolution Before File AccessN/A5.8 Medium0%Sep 17, 2026
CVE-2026-54575: Improper Neutralization of Special Elements used in an OS CommandN/A5.8 Medium0%Sep 17, 2026
CVE-2026-28326: Use of Hard-coded Cryptographic Key8.8 HighN/A1%Sep 17, 2026
CVE-2026-93015: Out-of-bounds Write6.3 Medium7.0 High0%Sep 17, 2026
CVE-2026-93014: Improper Limitation of a Pathname to a Restricted Directory7.1 High7.1 High1%Sep 17, 2026
CVE-2026-93013: Improper Limitation of a Pathname to a Restricted Directory4.3 Medium5.3 Medium1%Sep 17, 2026
CVE-2026-92881: Divide By Zero4.3 Medium5.3 Medium1%Sep 17, 2026
CVE-2026-91039: Authentication Bypass by SpoofingN/A9.1 Critical1%Sep 17, 2026
CVE-2026-89036: Improper Neutralization of Argument Delimiters in a Command8.8 High8.7 High1%Sep 17, 2026
CVE-2026-86864: Improper Neutralization of Argument Delimiters in a Command8.8 High8.7 High1%Sep 17, 2026
CVE-2026-86863: Authentication Bypass by Spoofing9.8 Critical9.3 Critical1%Sep 17, 2026
6676-6700 of 435847