The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-88952: Improper AuthenticationN/A9.1 Critical1%Sep 17, 2026
CVE-2026-87742: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Sep 17, 2026
CVE-2026-85078: Inconsistent Interpretation of HTTP Requests6.5 MediumN/A1%Sep 17, 2026
CVE-2026-85077: Improper Neutralization of CRLF Sequences in HTTP Headers8.2 HighN/A0%Sep 17, 2026
CVE-2026-81447: Improper Certificate Validation6.8 MediumN/A0%Sep 17, 2026
CVE-2026-81446: Server-Side Request Forgery (SSRF)7.4 HighN/A0%Sep 17, 2026
CVE-2026-81445: Improper Privilege Management7.2 HighN/A0%Sep 17, 2026
CVE-2026-80356: Exposure of Sensitive Information to an Unauthorized Actor7.3 HighN/A0%Sep 17, 2026
CVE-2026-79752: Improper Neutralization of Special Elements used in an SQL CommandN/A9.2 Critical1%Sep 17, 2026
CVE-2026-77614: Session Fixation8.8 HighN/A1%Sep 17, 2026
CVE-2026-71538: Improper Neutralization of Special Elements used in an OS CommandN/A8.5 High0%Sep 17, 2026
CVE-2026-63472: Improper Authentication9.1 CriticalN/A1%Sep 17, 2026
CVE-2026-63461: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Sep 17, 2026
CVE-2026-63460: Inefficient Regular Expression Complexity7.5 HighN/A1%Sep 17, 2026
CVE-2026-63459: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Sep 17, 2026
CVE-2026-61793: Improper Input ValidationN/A6.9 Medium0%Sep 17, 2026
CVE-2026-54471: Improper Handling of Insufficient Permissions or Privileges3.5 LowN/A0%Sep 17, 2026
CVE-2026-26950: Insufficient Verification of Data Authenticity8.1 HighN/A0%Sep 17, 2026
CVE-2026-92973: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Sep 17, 2026
CVE-2026-92972: Missing Authentication for Critical Function8.6 High8.8 High0%Sep 17, 2026
CVE-2026-92971: Reachable Assertion7.5 High8.7 High1%Sep 17, 2026
CVE-2026-92970: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High1%Sep 17, 2026
CVE-2026-92963: Undefined Security Weakness5.3 Medium6.9 Medium0%Sep 17, 2026
CVE-2026-92962: Protection Mechanism FailureN/A2.1 Low0%Sep 17, 2026
CVE-2026-92961: Allocation of Resources Without Limits or Throttling7.5 High8.7 High1%Sep 17, 2026
6926-6950 of 589307