The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-71464: Improper Neutralization of Argument Delimiters in a Command3.1 LowN/A0%Sep 23, 2026
CVE-2026-71463: Generation of Error Message Containing Sensitive Information2.7 LowN/A0%Sep 23, 2026
CVE-2026-71462: Observable Response Discrepancy4.1 MediumN/A0%Sep 23, 2026
CVE-2026-71461: Generation of Error Message Containing Sensitive Information4.3 MediumN/A0%Sep 23, 2026
CVE-2026-71460: Missing Authorization4.3 MediumN/A0%Sep 23, 2026
CVE-2026-63132: Observable Timing DiscrepancyN/A9.2 Critical0%Sep 23, 2026
CVE-2026-63131: Incorrect AuthorizationN/A6.0 Medium0%Sep 23, 2026
CVE-2026-61814: Uncontrolled Resource Consumption7.5 HighN/A1%Sep 23, 2026
CVE-2026-61695: Improper Validation of Array Index7.5 HighN/A1%Sep 23, 2026
CVE-2026-59990: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Sep 23, 2026
CVE-2026-55632: Incorrect Authorization4.3 MediumN/A0%Sep 23, 2026
CVE-2026-55456: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
CVE-2026-52744: Missing AuthorizationN/A5.3 Medium0%Sep 23, 2026
CVE-2026-91775: Improper Neutralization of Input During Web Page GenerationN/A7.4 High0%Sep 23, 2026
CVE-2026-88840: Out-of-bounds Read5.3 MediumN/A0%Sep 23, 2026
CVE-2026-88839: Out-of-bounds Write6.7 MediumN/A0%Sep 23, 2026
CVE-2026-88837: Authentication Bypass by Primary Weakness6.5 MediumN/A0%Sep 23, 2026
CVE-2026-88835: Out-of-bounds Read6.1 MediumN/A0%Sep 23, 2026
CVE-2026-88831: Not Failing Securely5.3 MediumN/A0%Sep 23, 2026
CVE-2026-86938: Authorization Bypass Through User-Controlled Key7.3 HighN/A0%Sep 23, 2026
CVE-2026-86934: Authorization Bypass Through User-Controlled Key9.1 CriticalN/A0%Sep 23, 2026
CVE-2026-86930: Out-of-bounds Read9.1 CriticalN/A0%Sep 23, 2026
CVE-2026-86926: Heap-based Buffer Overflow7.8 HighN/A0%Sep 23, 2026
CVE-2026-86867: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Sep 23, 2026
CVE-2026-18944: Undefined Security WeaknessN/AN/AN/ASep 23, 2026
6926-6950 of 402816