The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-93712: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Sep 22, 2026
CVE-2026-93711: Improper Neutralization of CRLF Sequences in HTTP Headers6.5 MediumN/A0%Sep 22, 2026
CVE-2026-93710: Improper Cleanup on Thrown Exception7.5 HighN/A0%Sep 22, 2026
CVE-2026-93709: Improper Resolution of Path Equivalence5.3 MediumN/A0%Sep 22, 2026
CVE-2026-76974: SAP_SE SAP Fiori Launchpad: SAP Fiori Launchpad does not sufficiently validate certain user-controlled input5.3 MediumN/A0%Sep 22, 2026
CVE-2026-94490: Improper Neutralization of Special Elements used in an OS Command4.7 Medium2.0 Low2%Sep 22, 2026
CVE-2026-94489: Improper Limitation of a Pathname to a Restricted Directory4.3 Medium2.1 Low0%Sep 22, 2026
CVE-2026-94426: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Sep 21, 2026
CVE-2026-94425: Improper Privilege Management8.8 High9.3 Critical0%Sep 21, 2026
CVE-2026-94627: Missing Release of Memory after Effective Lifetime7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94626: Memory Allocation with Excessive Size Value7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94625: Missing Release of Resource after Effective Lifetime5.3 Medium6.9 Medium0%Sep 21, 2026
CVE-2026-94624: Allocation of Resources Without Limits or Throttling7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94623: Reachable Assertion7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94622: Uncaught Exception7.5 High8.7 High0%Sep 21, 2026
CVE-2026-94540: Missing Authentication for Critical Function7.7 High7.4 High0%Sep 21, 2026
CVE-2026-94536: Authorization Bypass Through User-Controlled Key4.3 Medium5.3 Medium0%Sep 21, 2026
CVE-2026-94535: Authorization Bypass Through User-Controlled Key7.1 High7.1 High0%Sep 21, 2026
CVE-2026-94534: Authorization Bypass Through User-Controlled Key7.1 High7.1 High0%Sep 21, 2026
CVE-2026-94533: Authorization Bypass Through User-Controlled Key6.5 Medium7.1 High0%Sep 21, 2026
CVE-2026-94532: Authorization Bypass Through User-Controlled Key6.5 Medium7.1 High0%Sep 21, 2026
CVE-2026-93340: Weak Password Recovery Mechanism for Forgotten Password6.8 Medium7.4 High0%Sep 21, 2026
CVE-2026-88756: n/a: Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array…N/AN/A0%Sep 21, 2026
CVE-2026-88738: n/a: Jazzware RT1000 Edge webUI v8.8 HighN/A0%Sep 21, 2026
CVE-2026-79079: n/a: An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and…7.8 HighN/A0%Sep 21, 2026
951-975 of 559420