The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-76413: Improper Restriction of Security Token Assignment8.2 HighN/A0%Sep 16, 2026
CVE-2026-20350: Improper Neutralization of Special Elements used in an OS Command4.7 MediumN/A0%Sep 16, 2026
CVE-2026-20344: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Sep 16, 2026
CVE-2026-20300: Improper Neutralization of Special Elements used in an SQL Command7.1 HighN/A0%Sep 16, 2026
CVE-2026-20286: Improper Authorization4.3 MediumN/A0%Sep 16, 2026
CVE-2026-20285: Improper Authorization4.3 MediumN/A0%Sep 16, 2026
CVE-2026-20284: Improper Neutralization of Special Elements in Data Query Logic9.1 CriticalN/A0%Sep 16, 2026
CVE-2026-20283: Improper Neutralization of Special Elements used in an OS Command6.5 MediumN/A0%Sep 16, 2026
CVE-2026-20282: Improper Restriction of Names for Files and Other Resources4.9 MediumN/A1%Sep 16, 2026
CVE-2026-20235: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Sep 16, 2026
CVE-2026-20072: Incorrect Authorization4.9 MediumN/A0%Sep 16, 2026
CVE-2025-56566: Cleartext Storage of Sensitive Information4.6 MediumN/A0%Sep 16, 2026
CVE-2025-56565: Cleartext Storage of Sensitive Information7.6 HighN/A0%Sep 16, 2026
CVE-2026-92808: Server-Side Request Forgery (SSRF)N/A10.0 Critical1%Sep 16, 2026
CVE-2026-76423: Authentication Bypass by Spoofing10.0 CriticalN/A1%Sep 16, 2026
CVE-2026-20341: Deserialization of Untrusted Data9.1 CriticalN/A0%Sep 16, 2026
CVE-2026-20211: Deserialization of Untrusted Data9.1 CriticalN/A1%Sep 16, 2026
CVE-2026-20176: Improper Neutralization of Special Elements used in a Command9.1 CriticalN/A1%Sep 16, 2026
CVE-2026-73456: Improper Control of Generation of Code10.0 Critical9.2 Critical1%Sep 16, 2026
CVE-2026-92716: Authorization Bypass Through User-Controlled Key9.6 Critical8.6 High0%Sep 16, 2026
CVE-2026-87031: Missing Authorization2.7 Low2.1 Low0%Sep 16, 2026
CVE-2026-85386: Improper Neutralization of Input During Web Page Generation6.1 Medium7.3 High0%Sep 16, 2026
CVE-2026-85385: Improper Neutralization of Input During Web Page Generation9.6 Critical7.7 High0%Sep 16, 2026
CVE-2026-20307: Deserialization of Untrusted Data9.9 CriticalN/A1%Sep 16, 2026
CVE-2026-20306: Improper Neutralization of Special Elements used in an OS Command9.1 CriticalN/A1%Sep 16, 2026
651-675 of 17379