The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-88756: n/a: Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array…N/AN/A0%Sep 21, 2026
CVE-2026-88738: n/a: Jazzware RT1000 Edge webUI v8.8 HighN/A0%Sep 21, 2026
CVE-2026-79079: n/a: An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and…7.8 HighN/A0%Sep 21, 2026
CVE-2026-78847: n/a: An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to…9.8 CriticalN/A0%Sep 21, 2026
CVE-2026-78806: n/a: An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker…N/AN/A0%Sep 21, 2026
CVE-2026-65980: Improper Neutralization of Special Elements used in an SQL CommandN/A7.9 High0%Sep 21, 2026
CVE-2026-61852: Improper Neutralization of Special Elements used in an SQL CommandN/A5.8 Medium0%Sep 21, 2026
CVE-2026-61851: Incomplete List of Disallowed InputsN/A6.5 Medium0%Sep 21, 2026
CVE-2026-61743: Reliance on Reverse DNS Resolution for a Security-Critical Action6.3 MediumN/A0%Sep 21, 2026
CVE-2026-61541: Allocation of Resources Without Limits or ThrottlingN/A6.9 Medium0%Sep 21, 2026
CVE-2026-59830: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 21, 2026
CVE-2026-59815: Incorrect Authorization4.3 MediumN/A0%Sep 21, 2026
CVE-2026-59814: Improper Neutralization of Input During Web Page Generation7.6 HighN/A0%Sep 21, 2026
CVE-2026-55210: Authentication Bypass by Spoofing7.4 HighN/A0%Sep 21, 2026
CVE-2026-46650: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%Sep 21, 2026
CVE-2026-17054: Out-of-bounds Read5.3 MediumN/A0%Sep 21, 2026
CVE-2026-15890: Reusing a Nonce, Key Pair in Encryption5.3 MediumN/A0%Sep 21, 2026
CVE-2026-94588: Improper Neutralization of Argument Delimiters in a Command4.4 MediumN/A0%Sep 21, 2026
CVE-2026-94572: Improper Control of Generation of CodeN/A9.4 Critical0%Sep 21, 2026
CVE-2026-94571: Improper Control of Generation of CodeN/A9.4 Critical0%Sep 21, 2026
CVE-2026-94424: Heap-based Buffer Overflow8.8 High9.3 Critical0%Sep 21, 2026
CVE-2026-93433: Stack-based Buffer Overflow5.5 MediumN/A0%Sep 21, 2026
CVE-2026-88746: n/a: idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.7.1 HighN/A0%Sep 21, 2026
CVE-2026-88745: n/a: EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.6.1 MediumN/A0%Sep 21, 2026
CVE-2026-88467: n/a: CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of…N/AN/A0%Sep 21, 2026
976-1000 of 559420