The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-74909: Missing Authorization8.1 HighN/A1%Sep 16, 2026
CVE-2026-92467: Unverified Password Change8.3 High8.7 High0%Sep 16, 2026
CVE-2026-92466: Missing Authorization8.8 High8.7 High1%Sep 16, 2026
CVE-2026-92127: Improper Control of Generation of Code8.0 HighN/A1%Sep 16, 2026
CVE-2026-89030: Missing Authorization4.3 Medium5.3 Medium0%Sep 16, 2026
CVE-2026-73177: Insufficient Verification of Data AuthenticityN/A8.6 High0%Sep 16, 2026
CVE-2026-88817: Improper Privilege ManagementN/A8.7 High0%Sep 16, 2026
CVE-2026-73169: Improper Neutralization of Input During Web Page GenerationN/A6.3 Medium1%Sep 16, 2026
CVE-2026-19535: Cross-Site Request Forgery (CSRF)N/A8.6 High0%Sep 16, 2026
CVE-2026-40856: Missing Authentication for Critical FunctionN/A7.1 High0%Sep 16, 2026
CVE-2026-40854: Authentication Bypass by SpoofingN/A8.7 High0%Sep 16, 2026
CVE-2026-90039: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-90038: Undefined Security Weakness9.8 CriticalN/A1%Sep 16, 2026
CVE-2026-89975: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-89915: Undefined Security Weakness9.3 CriticalN/A0%Sep 16, 2026
CVE-2026-89852: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-82310: Insufficient Session Expiration7.2 HighN/A0%Sep 16, 2026
CVE-2026-73453: Improper Control of Generation of Code10.0 Critical9.5 Critical1%Sep 16, 2026
CVE-2026-14917: Authentication Bypass Using an Alternate Path or ChannelN/A7.7 High1%Sep 16, 2026
CVE-2026-86462: Insufficient Session Expiration9.1 CriticalN/A0%Sep 16, 2026
CVE-2026-82311: Insufficient Session Expiration9.8 CriticalN/A0%Sep 16, 2026
CVE-2026-73454: Improper Neutralization of Special Elements used in a Command8.1 High8.6 High0%Sep 16, 2026
CVE-2026-81326: Use of Hard-coded Cryptographic Key5.5 Medium6.8 Medium0%Sep 16, 2026
CVE-2026-13407: Improper Encoding or Escaping of Output5.4 MediumN/A0%Sep 16, 2026
CVE-2026-89327: Authentication Bypass by Spoofing3.8 LowN/A0%Sep 16, 2026
676-700 of 17376