The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-12995: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Sep 22, 2026
CVE-2025-1281: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A1%Sep 22, 2026
CVE-2025-1280: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Sep 22, 2026
CVE-2025-14487: Missing Authorization5.3 MediumN/A0%Sep 22, 2026
CVE-2025-14486: Missing Authorization5.3 MediumN/A0%Sep 22, 2026
CVE-2025-14484: Missing Authorization5.3 MediumN/A0%Sep 22, 2026
CVE-2016-15059: Heap-based Buffer Overflow9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-94504: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 22, 2026
CVE-2026-92438: Improper Neutralization of Input During Web Page Generation8.8 HighN/A0%Sep 22, 2026
CVE-2026-91827: Deserialization of Untrusted Data7.5 HighN/A0%Sep 22, 2026
CVE-2026-89412: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 22, 2026
CVE-2026-93655: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 22, 2026
CVE-2026-88788: Unknown Text Styler: The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before…6.8 MediumN/A0%Sep 22, 2026
CVE-2026-85653: ajay Contextual Related Posts: The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes'…6.4 MediumN/A0%Sep 22, 2026
CVE-2026-12470: Improper Privilege Management7.2 HighN/A0%Sep 22, 2026
CVE-2026-19658: Deserialization of Untrusted Data9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-13355: Improper Privilege Management9.8 CriticalN/A0%Sep 22, 2026
CVE-2026-94493: Missing Authentication for Critical Function10.0 Critical9.3 Critical1%Sep 22, 2026
CVE-2026-94492: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 22, 2026
CVE-2026-94491: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2026
CVE-2026-93712: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Sep 22, 2026
CVE-2026-93711: Improper Neutralization of CRLF Sequences in HTTP Headers6.5 MediumN/A0%Sep 22, 2026
CVE-2026-93710: Improper Cleanup on Thrown Exception7.5 HighN/A0%Sep 22, 2026
CVE-2026-93709: Improper Resolution of Path Equivalence5.3 MediumN/A0%Sep 22, 2026
CVE-2026-76974: SAP_SE SAP Fiori Launchpad: SAP Fiori Launchpad does not sufficiently validate certain user-controlled input5.3 MediumN/A0%Sep 22, 2026
926-950 of 559420