The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-105687: Improper Privilege Management4.9 MediumN/A0%Oct 5, 2026
CVE-2026-105677: Improper Limitation of a Pathname to a Restricted Directory7.2 HighN/A1%Oct 5, 2026
CVE-2026-105676: Improper Limitation of a Pathname to a Restricted Directory4.9 MediumN/A0%Oct 5, 2026
CVE-2026-105646: Inefficient Regular Expression Complexity4.9 MediumN/A0%Oct 5, 2026
CVE-2026-105645: Inefficient Regular Expression Complexity4.9 MediumN/A0%Oct 5, 2026
CVE-2026-105644: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Oct 5, 2026
CVE-2026-105634: Improper Privilege Management8.1 HighN/A0%Oct 5, 2026
CVE-2026-105630: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Oct 5, 2026
CVE-2026-105629: Authorization Bypass Through User-Controlled Key7.1 HighN/A0%Oct 5, 2026
CVE-2026-104976: Server-Side Request Forgery (SSRF)N/A8.7 High0%Oct 5, 2026
CVE-2026-104974: Improper Access Control8.1 HighN/A1%Oct 5, 2026
CVE-2026-105382: Improper Authorization7.3 High5.5 Medium0%Oct 5, 2026
CVE-2026-104970: Concurrent Execution using Shared Resource with Improper Synchronization8.1 HighN/A0%Oct 5, 2026
CVE-2026-104967: Authorization Bypass Through User-Controlled Key5.4 MediumN/A0%Oct 5, 2026
CVE-2026-104964: Authorization Bypass Through User-Controlled Key6.8 MediumN/A0%Oct 5, 2026
CVE-2026-102777: Server-Side Request Forgery (SSRF)N/A6.3 Medium0%Oct 5, 2026
CVE-2026-102776: Cross-Site Request Forgery (CSRF)N/A5.1 Medium0%Oct 5, 2026
CVE-2026-77805: Improper Verification of Cryptographic Signature7.9 HighN/A0%Oct 5, 2026
CVE-2026-59782: Out-of-bounds ReadN/A6.9 Medium0%Oct 5, 2026
CVE-2026-104706: Path Traversal: 'dir\..\..\filename'N/A8.4 High0%Oct 5, 2026
CVE-2026-105302: Exposure of Sensitive Information to an Unauthorized Actor5.7 MediumN/A0%Oct 5, 2026
CVE-2026-105211: Exposure of Sensitive Information to an Unauthorized Actor8.1 High9.2 Critical0%Oct 4, 2026
CVE-2026-93549: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Oct 4, 2026
CVE-2026-104119: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Oct 4, 2026
CVE-2026-105124: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Oct 4, 2026
51-75 of 17414