The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-18110: Missing Authorization7.5 High8.7 High0%Sep 15, 2026
CVE-2026-91985: Exposure of Sensitive Information to an Unauthorized Actor7.5 High8.7 High0%Sep 15, 2026
CVE-2026-91930: Incorrect Privilege Assignment7.5 High7.7 High0%Sep 15, 2026
CVE-2026-88621: Use of Incorrectly-Resolved Name or Reference2.7 LowN/A0%Sep 15, 2026
CVE-2026-88619: Missing Authorization8.1 HighN/A0%Sep 15, 2026
CVE-2026-65831: Improper Privilege Management7.7 HighN/A1%Sep 15, 2026
CVE-2026-59973: Server-Side Request Forgery (SSRF)8.5 HighN/A0%Sep 15, 2026
CVE-2026-59965: Incorrect Authorization7.1 HighN/A0%Sep 15, 2026
CVE-2026-54077: Improper Limitation of a Pathname to a Restricted Directory7.1 HighN/A0%Sep 15, 2026
CVE-2026-47215: Improper Limitation of a Pathname to a Restricted Directory4.8 MediumN/A0%Sep 15, 2026
CVE-2026-44282: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Sep 15, 2026
CVE-2026-92082: Improper Restriction of Excessive Authentication AttemptsN/A6.3 Medium0%Sep 15, 2026
CVE-2026-90650: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 15, 2026
CVE-2026-90439: Heap-based Buffer Overflow6.5 Medium6.9 Medium0%Sep 15, 2026
CVE-2026-61549: Improper Privilege ManagementN/A9.0 Critical0%Sep 15, 2026
CVE-2026-50166: Improper Certificate ValidationN/A5.5 Medium0%Sep 15, 2026
CVE-2026-49254: Exposure of Sensitive Information to an Unauthorized ActorN/A2.9 Low0%Sep 15, 2026
CVE-2026-14805: Improper Privilege Management8.8 HighN/A0%Sep 15, 2026
CVE-2026-91998: Incorrect Authorization9.9 Critical9.4 Critical1%Sep 15, 2026
CVE-2026-91995: Unverified Password Change9.1 Critical9.3 Critical1%Sep 15, 2026
CVE-2026-52828: Missing AuthorizationN/A5.3 Medium0%Sep 15, 2026
CVE-2026-52822: Improper AuthorizationN/A5.3 Medium0%Sep 15, 2026
CVE-2026-47424: Protection Mechanism FailureN/A7.5 High0%Sep 15, 2026
CVE-2026-45052: Improper AuthorizationN/A9.3 Critical1%Sep 15, 2026
CVE-2026-45051: Deserialization of Untrusted DataN/A9.2 Critical1%Sep 15, 2026
751-775 of 17375