The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-92882: Insufficiently Protected CredentialsN/A5.3 Medium0%Sep 22, 2026
CVE-2026-90990: Improper Neutralization of CRLF SequencesN/A5.3 Medium0%Sep 22, 2026
CVE-2026-94117: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Sep 22, 2026
CVE-2026-90882: Permissive Cross-domain Policy with Untrusted DomainsN/A8.7 High0%Sep 22, 2026
CVE-2026-25265: Creation of Temporary File With Insecure Permissions8.8 HighN/A0%Sep 22, 2026
CVE-2026-25264: Uncontrolled Search Path Element8.8 HighN/A0%Sep 22, 2026
CVE-2026-25262: Write-what-where Condition6.9 MediumN/A0%Sep 22, 2026
CVE-2026-25255: Exposed Dangerous Method or Function8.8 HighN/A0%Sep 22, 2026
CVE-2026-25254: Improper Authorization9.8 CriticalN/A1%Sep 22, 2026
CVE-2026-9231: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A1%Sep 22, 2026
CVE-2026-95508: Out-of-bounds Write7.4 HighN/A0%Sep 22, 2026
CVE-2026-93928: Authentication Bypass Using an Alternate Path or Channel7.3 HighN/A0%Sep 22, 2026
CVE-2026-93556: Authorization Bypass Through User-Controlled KeyN/A9.3 Critical0%Sep 22, 2026
CVE-2026-89422: Key Exchange without Entity AuthenticationN/A9.3 Critical0%Sep 22, 2026
CVE-2026-68956: Allocation of Resources Without Limits or ThrottlingN/A7.1 High0%Sep 22, 2026
CVE-2026-65634: Inefficient Algorithmic ComplexityN/A8.2 High0%Sep 22, 2026
CVE-2026-15095: Improper Limitation of a Pathname to a Restricted Directory4.9 MediumN/A1%Sep 22, 2026
CVE-2026-95511: Undefined Security WeaknessN/AN/A0%Sep 22, 2026
CVE-2026-9004: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Sep 22, 2026
CVE-2026-95503: Improper Verification of Cryptographic Signature6.8 MediumN/A0%Sep 22, 2026
CVE-2026-93952: Improper Input Validation10.0 Critical9.5 Critical1%Sep 22, 2026
CVE-2026-93836: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 22, 2026
CVE-2026-93778: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 22, 2026
CVE-2026-92969: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Sep 22, 2026
CVE-2026-92235: Improper Control of Generation of Code8.1 HighN/A0%Sep 22, 2026
876-900 of 395809