The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-18490: Deserialization of Untrusted Data8.8 HighN/A0%Sep 23, 2026
CVE-2026-18185: Missing Authentication for Critical Function7.3 HighN/A0%Sep 23, 2026
CVE-2026-18184: Improper Restriction of XML External Entity Reference7.4 HighN/A0%Sep 23, 2026
CVE-2026-18181: Use of Hard-coded Cryptographic Key8.1 HighN/A0%Sep 23, 2026
CVE-2026-18180: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Sep 23, 2026
CVE-2026-96673: Improper Neutralization of Special Elements used in an SQL Command7.5 High8.7 High0%Sep 23, 2026
CVE-2026-96611: Integer Overflow or Wraparound6.9 MediumN/A0%Sep 23, 2026
CVE-2026-96609: Allocation of Resources Without Limits or ThrottlingN/A7.1 High0%Sep 23, 2026
CVE-2026-96600: Improper Neutralization of Special Elements used in an SQL Command5.5 Medium7.0 High0%Sep 23, 2026
CVE-2026-96599: Use of Insufficiently Random Values5.9 Medium8.2 High0%Sep 23, 2026
CVE-2026-96276: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Sep 23, 2026
CVE-2026-96275: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A0%Sep 23, 2026
CVE-2026-92419: Authorization Bypass Through User-Controlled KeyN/A5.3 Medium0%Sep 23, 2026
CVE-2026-92164: External Control of File Name or Path6.5 MediumN/A0%Sep 23, 2026
CVE-2026-88974: Incorrect Authorization5.4 MediumN/A0%Sep 23, 2026
CVE-2026-73858: Improper Neutralization of Special Elements Used in a Template Engine5.3 MediumN/A0%Sep 23, 2026
CVE-2026-73591: Inclusion of Sensitive Information in Source Code7.5 HighN/A0%Sep 23, 2026
CVE-2026-73589: Weak Encoding for Password6.3 MediumN/A0%Sep 23, 2026
CVE-2026-73588: Missing Authentication for Critical Function7.4 HighN/A0%Sep 23, 2026
CVE-2026-73587: Improper Certificate Validation6.8 MediumN/A0%Sep 23, 2026
CVE-2026-73586: Insufficient Session Expiration6.4 MediumN/A0%Sep 23, 2026
CVE-2026-71178: Use of Non-Canonical URL Paths for Authorization Decisions3.7 LowN/A0%Sep 23, 2026
CVE-2026-71177: Improper Restriction of Rendered UI Layers or Frames5.4 MediumN/A0%Sep 23, 2026
CVE-2026-63002: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Sep 23, 2026
CVE-2026-63001: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Sep 23, 2026
7001-7025 of 402816