The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-76689: Stack-based Buffer Overflow7.2 HighN/A1%Sep 15, 2026
CVE-2026-76688: Improper Authentication7.5 HighN/A0%Sep 15, 2026
CVE-2026-76684: Improper Authentication8.1 HighN/A0%Sep 15, 2026
CVE-2026-76677: Improper Privilege Management8.8 HighN/A0%Sep 15, 2026
CVE-2026-76673: Improper Authentication9.8 CriticalN/A0%Sep 15, 2026
CVE-2026-76670: Improper Privilege Management9.9 CriticalN/A0%Sep 15, 2026
CVE-2026-76669: Improper Privilege Management9.9 CriticalN/A0%Sep 15, 2026
CVE-2026-81924: Cross-Site Request Forgery (CSRF)6.5 Medium2.1 Low0%Sep 15, 2026
CVE-2026-81920: Cross-Site Request Forgery (CSRF)4.3 Medium2.3 Low0%Sep 15, 2026
CVE-2026-79411: Improper Privilege Management8.8 HighN/A0%Sep 15, 2026
CVE-2026-73466: Insertion of Sensitive Information into Log File6.3 Medium6.0 Medium0%Sep 15, 2026
CVE-2026-73465: Insertion of Sensitive Information into Log File6.3 Medium6.0 Medium0%Sep 15, 2026
CVE-2026-68534: Improper Neutralization of Input During Web Page GenerationN/A2.3 Low1%Sep 15, 2026
CVE-2026-81899: Improper Neutralization of Input During Web Page GenerationN/A7.3 High0%Sep 15, 2026
CVE-2026-56831: Improper Input Validation6.5 MediumN/A0%Sep 15, 2026
CVE-2026-54050: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Sep 15, 2026
CVE-2026-48785: Improper Limitation of a Pathname to a Restricted Directory4.8 MediumN/A0%Sep 15, 2026
CVE-2026-18113: Improper Neutralization of Input During Web Page GenerationN/A7.5 High0%Sep 15, 2026
CVE-2026-12101: Authentication Bypass by Alternate Name8.1 HighN/A0%Sep 15, 2026
CVE-2026-11934: Improper Authorization7.2 HighN/A0%Sep 15, 2026
CVE-2026-81897: Cross-Site Request Forgery (CSRF)5.4 Medium7.7 High0%Sep 15, 2026
CVE-2026-81896: Improper Neutralization of Input During Web Page Generation5.4 Medium8.4 High0%Sep 15, 2026
CVE-2026-55863: Missing Authorization5.3 MediumN/A0%Sep 15, 2026
CVE-2026-46488: Plaintext Storage of a PasswordN/A9.1 Critical0%Sep 15, 2026
CVE-2026-18111: Missing Authentication for Critical FunctionN/A8.5 High0%Sep 15, 2026
726-750 of 17375