The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-90903: Cross-Site Request Forgery (CSRF)N/A7.2 High0%Sep 23, 2026
CVE-2026-90902: Improper Neutralization of Special Elements used in an SQL CommandN/A8.6 High0%Sep 23, 2026
CVE-2026-90901: Improper Neutralization of Special Elements used in an SQL CommandN/A8.6 High0%Sep 23, 2026
CVE-2026-90900: Cross-Site Request Forgery (CSRF)N/A5.3 Medium0%Sep 23, 2026
CVE-2026-90899: Exposure of Sensitive Information to an Unauthorized ActorN/A8.2 High0%Sep 23, 2026
CVE-2026-84502: Improper Neutralization of Argument Delimiters in a Command9.9 CriticalN/A1%Sep 23, 2026
CVE-2026-84499: Generation of Error Message Containing Sensitive Information7.7 HighN/A0%Sep 23, 2026
CVE-2026-84486: Active Debug Code8.2 HighN/A1%Sep 23, 2026
CVE-2026-84474: Reliance on Untrusted Inputs in a Security Decision9.9 CriticalN/A1%Sep 23, 2026
CVE-2026-82368: Improper Access ControlN/A8.7 High0%Sep 23, 2026
CVE-2026-82356: Inadequate Encryption Strength7.5 HighN/A0%Sep 23, 2026
CVE-2026-77602: Improper Control of Generation of Code9.9 CriticalN/A1%Sep 23, 2026
CVE-2026-77601: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-77423: Inefficient Regular Expression Complexity7.5 HighN/A0%Sep 23, 2026
CVE-2026-77422: Inefficient Regular Expression Complexity7.5 HighN/A0%Sep 23, 2026
CVE-2026-77421: Inefficient Regular Expression Complexity6.5 MediumN/A0%Sep 23, 2026
CVE-2026-77420: Inefficient Regular Expression Complexity5.5 MediumN/A0%Sep 23, 2026
CVE-2026-77394: Improper Neutralization of Input During Web Page Generation7.6 HighN/A0%Sep 23, 2026
CVE-2026-77285: Insertion of Sensitive Information into Log FileN/A2.4 Low0%Sep 23, 2026
CVE-2026-76648: Missing Authorization8.5 HighN/A0%Sep 23, 2026
CVE-2026-76089: Exposure of Sensitive Information to an Unauthorized Actor7.7 HighN/A0%Sep 23, 2026
CVE-2026-76087: Authorization Bypass Through User-Controlled Key8.2 HighN/A0%Sep 23, 2026
CVE-2026-76086: Missing Authorization8.5 HighN/A0%Sep 23, 2026
CVE-2026-75131: Improper Neutralization of Argument Delimiters in a Command7.8 High8.5 High0%Sep 23, 2026
CVE-2026-71465: Improper Neutralization of Argument Delimiters in a Command3.1 LowN/A0%Sep 23, 2026
6901-6925 of 402816