The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-95503: Improper Verification of Cryptographic Signature6.8 MediumN/A0%Sep 22, 2026
CVE-2026-93952: Improper Input Validation10.0 Critical9.5 Critical1%Sep 22, 2026
CVE-2026-93836: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 22, 2026
CVE-2026-93778: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 22, 2026
CVE-2026-92969: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Sep 22, 2026
CVE-2026-92235: Improper Control of Generation of Code8.1 HighN/A0%Sep 22, 2026
CVE-2026-91092: Missing Authorization4.3 MediumN/A0%Sep 22, 2026
CVE-2026-87082: Loop with Unreachable Exit Condition ('Infinite Loop')7.5 HighN/A0%Sep 22, 2026
CVE-2026-87081: Inefficient Algorithmic Complexity7.5 HighN/A0%Sep 22, 2026
CVE-2026-87080: Improper Validation of Syntactic Correctness of Input9.1 CriticalN/A0%Sep 22, 2026
CVE-2026-87079: Inefficient Algorithmic Complexity7.5 HighN/A0%Sep 22, 2026
CVE-2026-87078: Missing Release of Memory after Effective Lifetime9.1 CriticalN/A0%Sep 22, 2026
CVE-2026-7622: codexpert: The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.14.3 MediumN/A0%Sep 22, 2026
CVE-2026-74766: Use After Free8.4 HighN/A0%Sep 22, 2026
CVE-2026-74765: Integer Overflow or Wraparound6.5 MediumN/A0%Sep 22, 2026
CVE-2026-6922: Incorrect Authorization7.1 HighN/A0%Sep 22, 2026
CVE-2026-4123: Missing Authorization4.3 MediumN/A0%Sep 22, 2026
CVE-2026-1645: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%Sep 22, 2026
CVE-2026-18439: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Sep 22, 2026
CVE-2026-18345: Missing Authorization4.3 MediumN/A0%Sep 22, 2026
CVE-2026-16778: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 22, 2026
CVE-2026-12995: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Sep 22, 2026
CVE-2025-1281: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A1%Sep 22, 2026
CVE-2025-1280: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Sep 22, 2026
CVE-2025-14487: Missing Authorization5.3 MediumN/A0%Sep 22, 2026
901-925 of 559420