The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-82186: Improper Neutralization of Special Elements used in an SQL Command4.1 MediumN/A0%Sep 4, 2026
CVE-2026-80438: Improper Access Control5.9 MediumN/A0%Sep 4, 2026
CVE-2026-19224: Improper Control of Generation of Code7.2 HighN/A0%Sep 4, 2026
CVE-2026-15354: Improper Privilege Management9.8 CriticalN/A0%Sep 4, 2026
CVE-2026-18330: Use of Hard-coded Cryptographic KeyN/A6.1 Medium0%Sep 3, 2026
CVE-2026-85392: Authorization Bypass Through User-Controlled Key4.3 Medium5.3 Medium0%Sep 3, 2026
CVE-2026-85390: Missing Authorization7.1 High7.1 High0%Sep 3, 2026
CVE-2026-78583: Incorrect Authorization8.1 HighN/A0%Sep 3, 2026
CVE-2026-82024: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Sep 3, 2026
CVE-2026-83961: Improper Authentication7.1 HighN/A0%Sep 3, 2026
CVE-2026-75035: Authorization Bypass Through User-Controlled Key6.5 Medium7.1 High0%Sep 3, 2026
CVE-2026-85216: Weak Password Requirements9.8 Critical9.5 Critical0%Sep 3, 2026
CVE-2026-85214: Authorization Bypass Through User-Controlled Key8.1 High7.2 High0%Sep 3, 2026
CVE-2026-85212: Missing Authorization8.3 High8.7 High0%Sep 3, 2026
CVE-2026-84989: Missing Authorization7.1 HighN/A0%Sep 3, 2026
CVE-2026-80515: Use of Non-Canonical URL Paths for Authorization DecisionsN/A8.9 High0%Sep 3, 2026
CVE-2025-12737: Improper Neutralization of Special Elements used in an OS Command8.4 HighN/A0%Sep 3, 2026
CVE-2026-9854: Incorrect Implementation of Authentication Algorithm7.8 High8.5 High0%Sep 3, 2026
CVE-2026-85175: Files or Directories Accessible to External Parties8.8 High8.7 High0%Sep 3, 2026
CVE-2026-85174: Insertion of Sensitive Information into Log File8.8 High8.7 High0%Sep 3, 2026
CVE-2026-85154: Improper Privilege Management9.8 Critical9.3 Critical0%Sep 3, 2026
CVE-2026-84830: Improper Neutralization of Special Elements used in an OS CommandN/A8.6 High1%Sep 3, 2026
CVE-2026-76178: Improper Neutralization of Input During Web Page GenerationN/A9.2 Critical0%Sep 3, 2026
CVE-2026-76174: Unrestricted Upload of File with Dangerous TypeN/A9.4 Critical0%Sep 3, 2026
CVE-2026-15933: Plaintext Storage of a PasswordN/A6.9 Medium0%Sep 3, 2026
1076-1100 of 17379