The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-92934: Protection Mechanism Failure9.0 Critical9.5 Critical1%Sep 17, 2026
CVE-2026-92933: Exposure of Sensitive Information to an Unauthorized Actor5.8 Medium6.9 Medium0%Sep 17, 2026
CVE-2026-92879: Uncontrolled Resource Consumption4.3 Medium5.3 Medium1%Sep 17, 2026
CVE-2026-90986: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 17, 2026
CVE-2026-90887: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 17, 2026
CVE-2026-89418: Uncontrolled RecursionN/A8.7 High0%Sep 17, 2026
CVE-2026-86533: Insufficient Session ExpirationN/A9.1 Critical1%Sep 17, 2026
CVE-2026-86522: Improper Output Neutralization for LogsN/A6.3 Medium1%Sep 17, 2026
CVE-2026-85500: Authentication Bypass by Primary WeaknessN/A9.1 Critical1%Sep 17, 2026
CVE-2026-82761: Time-of-check Time-of-use (TOCTOU) Race ConditionN/A9.1 Critical1%Sep 17, 2026
CVE-2026-82760: Inefficient Algorithmic ComplexityN/A8.2 High1%Sep 17, 2026
CVE-2026-82759: Use of a One-Way Hash with a Predictable SaltN/A1.8 Low0%Sep 17, 2026
CVE-2026-82723: Insertion of Sensitive Information into Log FileN/A1.8 Low0%Sep 17, 2026
CVE-2026-82685: Authorization Bypass Through User-Controlled KeyN/A7.6 High1%Sep 17, 2026
CVE-2026-81829: Improper Limitation of a Pathname to a Restricted Directory5.3 MediumN/A0%Sep 17, 2026
CVE-2026-81637: Insufficient Session ExpirationN/A2.3 Low1%Sep 17, 2026
CVE-2026-81632: Use of GET Request Method With Sensitive Query StringsN/A7.2 High0%Sep 17, 2026
CVE-2026-81453: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Sep 17, 2026
CVE-2026-81443: Server-Side Request Forgery (SSRF)6.4 MediumN/A0%Sep 17, 2026
CVE-2026-81442: Improper Privilege Management8.1 HighN/A0%Sep 17, 2026
CVE-2026-80355: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Sep 17, 2026
CVE-2026-80218: Improper AuthenticationN/A7.6 High1%Sep 17, 2026
CVE-2026-78528: Missing Authorization5.3 MediumN/A0%Sep 17, 2026
CVE-2026-78295: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 17, 2026
CVE-2026-78294: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 17, 2026
6976-7000 of 589307