The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-71459: Missing Authorization5.0 MediumN/A0%Sep 23, 2026
CVE-2026-71458: Observable Response Discrepancy5.0 MediumN/A0%Sep 23, 2026
CVE-2026-96808: UNIX Symbolic Link (Symlink) Following7.4 HighN/A0%Sep 23, 2026
CVE-2026-96807: UNIX Symbolic Link (Symlink) Following4.0 MediumN/A0%Sep 23, 2026
CVE-2026-96804: Deserialization of Untrusted Data8.8 HighN/A0%Sep 23, 2026
CVE-2026-96775: Deserialization of Untrusted Data8.8 HighN/A0%Sep 23, 2026
CVE-2026-96759: Improper Control of Generation of Code9.8 Critical9.3 Critical0%Sep 23, 2026
CVE-2026-96758: Improper Control of Generation of Code9.8 Critical9.3 Critical1%Sep 23, 2026
CVE-2026-96757: Improper Control of Generation of Code9.8 Critical9.3 Critical1%Sep 23, 2026
CVE-2026-96756: Improper Control of Generation of Code8.1 High9.2 Critical0%Sep 23, 2026
CVE-2026-96755: Improper Control of Generation of Code9.8 Critical9.3 Critical0%Sep 23, 2026
CVE-2026-96754: Improper Control of Generation of Code9.8 Critical9.3 Critical0%Sep 23, 2026
CVE-2026-96656: External Control of File Name or Path7.2 High8.6 High0%Sep 23, 2026
CVE-2026-96655: Server-Side Request Forgery (SSRF)4.3 Medium5.3 Medium0%Sep 23, 2026
CVE-2026-96654: Improper Neutralization of Encoded URI Schemes in a Web Page6.5 Medium6.9 Medium0%Sep 23, 2026
CVE-2026-96652: Server-Side Request Forgery (SSRF)4.3 Medium5.3 Medium0%Sep 23, 2026
CVE-2026-96651: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium7.1 High1%Sep 23, 2026
CVE-2026-96514: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-96513: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium0%Sep 23, 2026
CVE-2026-95848: Not Failing Securely9.1 Critical9.3 Critical0%Sep 23, 2026
CVE-2026-95847: Improper Control of Resource Identifiers7.5 High8.8 High0%Sep 23, 2026
CVE-2026-95846: Missing Authorization7.5 High8.7 High0%Sep 23, 2026
CVE-2026-95845: Allocation of Resources Without Limits or Throttling7.5 High8.7 High0%Sep 23, 2026
CVE-2026-95844: Uncontrolled Recursion7.5 High8.7 High0%Sep 23, 2026
CVE-2026-95843: Improper Input Validation7.5 High8.7 High0%Sep 23, 2026
6951-6975 of 402816