The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-82846: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Sep 5, 2026
CVE-2026-81348: Exposure of Sensitive Information to an Unauthorized Actor3.7 LowN/A0%Sep 5, 2026
CVE-2026-78362: Improper Privilege Management9.8 CriticalN/A0%Sep 5, 2026
CVE-2026-19861: Improper Neutralization of Input During Web Page Generation4.7 MediumN/A0%Sep 5, 2026
CVE-2025-15694: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Sep 5, 2026
CVE-2025-15693: Improper Limitation of a Pathname to a Restricted Directory2.7 LowN/A0%Sep 5, 2026
CVE-2026-83628: Missing Authorization4.3 MediumN/A0%Sep 5, 2026
CVE-2026-83627: Improper Control of Generation of Code9.8 CriticalN/A1%Sep 5, 2026
CVE-2026-77263: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 5, 2026
CVE-2026-52762: Improper Neutralization of Special Elements Used in a Template EngineN/A7.1 High0%Sep 5, 2026
CVE-2026-86091: Missing Authorization7.1 High7.1 High0%Sep 4, 2026
CVE-2026-86090: Missing Authorization7.1 High7.1 High0%Sep 4, 2026
CVE-2026-53769: Missing Authorization6.5 MediumN/A0%Sep 4, 2026
CVE-2026-82538: Improper Neutralization of Special Elements used in an SQL Command8.8 High8.7 High1%Sep 4, 2026
CVE-2026-80892: Undefined Security WeaknessN/AN/A0%Sep 4, 2026
CVE-2026-57166: Stack-based Buffer Overflow5.3 Medium6.3 Medium0%Sep 4, 2026
CVE-2026-53760: Cross-Site Request Forgery (CSRF)5.2 MediumN/A0%Sep 4, 2026
CVE-2026-14466: Improper Neutralization of Input During Web Page Generation4.3 MediumN/A0%Sep 4, 2026
CVE-2026-85600: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Sep 4, 2026
CVE-2026-85599: Improper Neutralization of Input During Web Page Generation7.2 High5.1 Medium0%Sep 4, 2026
CVE-2026-85598: Improper Neutralization of Input During Web Page Generation6.4 Medium5.1 Medium0%Sep 4, 2026
CVE-2026-85591: Unverified Password ChangeN/A7.1 High0%Sep 4, 2026
CVE-2026-85590: Use of Single-factor AuthenticationN/A7.1 High0%Sep 4, 2026
CVE-2026-82194: External Control of File Name or Path5.5 MediumN/A0%Sep 4, 2026
CVE-2026-82193: Improper Limitation of a Pathname to a Restricted Directory5.5 MediumN/A0%Sep 4, 2026
1051-1075 of 17379