The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-76979: XML Injection (aka Blind XPath Injection)7.7 HighN/A1%Sep 23, 2026
CVE-2026-76978: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A4%Sep 23, 2026
CVE-2026-75825: Missing Authentication for Critical Function8.8 HighN/A1%Sep 23, 2026
CVE-2026-19599: Improper Neutralization of Special Elements used in an OS Command9.9 CriticalN/A3%Sep 23, 2026
CVE-2026-96446: Missing Authorization4.2 MediumN/A0%Sep 23, 2026
CVE-2026-96445: Improper Authentication6.8 MediumN/A0%Sep 23, 2026
CVE-2026-87022: Improper Handling of Length Parameter Inconsistency7.5 HighN/A0%Sep 23, 2026
CVE-2026-86350: Inconsistent Interpretation of HTTP Requests9.1 CriticalN/A0%Sep 23, 2026
CVE-2026-86248: Improper Authentication9.8 CriticalN/A0%Sep 23, 2026
CVE-2026-84791: Authorization Bypass Through User-Controlled Key7.1 HighN/A1%Sep 23, 2026
CVE-2026-84789: Authorization Bypass Through User-Controlled Key7.1 HighN/A1%Sep 23, 2026
CVE-2026-84787: Execution with Unnecessary Privileges8.1 HighN/A1%Sep 23, 2026
CVE-2026-80444: URL Redirection to Untrusted Site5.4 MediumN/A0%Sep 23, 2026
CVE-2026-79677: Missing Release of Resource after Effective Lifetime7.5 HighN/A0%Sep 23, 2026
CVE-2026-78437: Incomplete Cleanup7.3 HighN/A0%Sep 23, 2026
CVE-2026-78383: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Sep 23, 2026
CVE-2026-78253: Uncontrolled RecursionN/A2.3 Low0%Sep 23, 2026
CVE-2026-77791: Uncontrolled Resource Consumption7.5 HighN/A1%Sep 23, 2026
CVE-2026-77762: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A0%Sep 23, 2026
CVE-2026-77756: Inconsistent Interpretation of HTTP Requests3.7 LowN/A0%Sep 23, 2026
CVE-2026-76183: Authentication Bypass by Alternate Name9.8 CriticalN/A0%Sep 23, 2026
CVE-2026-75973: Improper Authentication7.3 HighN/A0%Sep 23, 2026
CVE-2026-73581: Improper Check for Certificate Revocation6.5 MediumN/A0%Sep 23, 2026
CVE-2026-15358: Unquoted Search Path or Element7.5 HighN/A1%Sep 23, 2026
CVE-2026-14913: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A1%Sep 23, 2026
7051-7075 of 402816