The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-94176: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-94174: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 23, 2026
CVE-2026-94168: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94124: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Sep 23, 2026
CVE-2026-94118: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-94080: Missing Authorization5.3 MediumN/A0%Sep 23, 2026
CVE-2026-94079: Missing Authorization5.3 MediumN/A0%Sep 23, 2026
CVE-2026-93774: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-93773: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Sep 23, 2026
CVE-2026-93772: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-93623: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Sep 23, 2026
CVE-2026-93622: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-93620: Missing Authorization6.5 MediumN/A0%Sep 23, 2026
CVE-2026-93618: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-93529: Missing Authorization6.5 MediumN/A0%Sep 23, 2026
CVE-2026-93527: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Sep 23, 2026
CVE-2026-93526: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-93513: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Sep 23, 2026
CVE-2026-93421: Improper Output Neutralization for LogsN/A5.3 Medium0%Sep 23, 2026
CVE-2026-92730: Improper Neutralization of Input During Web Page GenerationN/A7.4 High0%Sep 23, 2026
CVE-2026-92700: Improper Handling of Case SensitivityN/A6.3 Medium0%Sep 23, 2026
CVE-2026-92692: Improper Neutralization of Special Elements used in an SQL CommandN/A6.9 Medium0%Sep 23, 2026
CVE-2026-92284: Allocation of Resources Without Limits or ThrottlingN/A6.9 Medium0%Sep 23, 2026
CVE-2026-90905: Cross-Site Request Forgery (CSRF)N/A7.2 High0%Sep 23, 2026
CVE-2026-90904: Improper Access ControlN/A8.6 High0%Sep 23, 2026
6876-6900 of 402816