The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-43613: Incorrect Permission Assignment for Critical Resource6.5 MediumN/A0%Sep 3, 2026
CVE-2026-82524: Unrestricted Upload of File with Dangerous Type7.2 High8.6 High0%Sep 2, 2026
CVE-2026-77125: Incorrect Authorization7.1 High7.1 High0%Sep 2, 2026
CVE-2026-77124: Incomplete List of Disallowed Inputs7.2 High7.5 High0%Sep 2, 2026
CVE-2026-77121: Allocation of Resources Without Limits or Throttling6.5 Medium5.3 Medium0%Sep 2, 2026
CVE-2026-55221: Insertion of Sensitive Information into Log File6.5 MediumN/A0%Sep 2, 2026
CVE-2026-49833: Improper Limitation of a Pathname to a Restricted Directory5.5 MediumN/A0%Sep 2, 2026
CVE-2026-49830: Improper Input Validation4.4 MediumN/A0%Sep 2, 2026
CVE-2026-84664: Modification of Assumed-Immutable Data (MAID)5.4 MediumN/A0%Sep 2, 2026
CVE-2026-66842: Server-Side Request Forgery (SSRF)8.8 High8.7 High0%Sep 2, 2026
CVE-2026-14199: Authentication Bypass by Spoofing8.1 HighN/A0%Sep 2, 2026
CVE-2026-8151: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Sep 2, 2026
CVE-2026-79989: Improper AuthorizationN/A8.7 High0%Sep 2, 2026
CVE-2026-78599: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Sep 2, 2026
CVE-2026-78591: Improper Limitation of a Pathname to a Restricted Directory6.3 MediumN/A0%Sep 2, 2026
CVE-2026-78590: Improper Limitation of a Pathname to a Restricted Directory7.3 HighN/A0%Sep 2, 2026
CVE-2025-15692: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Sep 2, 2026
CVE-2026-84807: Incorrect Privilege Assignment5.4 Medium5.3 Medium0%Sep 2, 2026
CVE-2026-84801: Missing Authorization8.8 High8.7 High0%Sep 2, 2026
CVE-2026-84799: Improper Authorization4.3 Medium5.3 Medium0%Sep 2, 2026
CVE-2026-84795: Improper Privilege Management9.8 Critical9.2 Critical0%Sep 2, 2026
CVE-2026-84793: Improper Neutralization of Input During Web Page Generation4.8 Medium4.8 Medium0%Sep 2, 2026
CVE-2026-82958: Improper Neutralization of Special Elements Used in a Template EngineN/A7.6 High0%Sep 2, 2026
CVE-2026-75528: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Sep 2, 2026
CVE-2026-82183: Improper Authentication8.1 HighN/A0%Sep 2, 2026
1101-1125 of 17379