The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-73547: Improper Input Validation7.5 HighN/A1%Sep 21, 2026
CVE-2026-73546: Improper Neutralization of Input During Web Page Generation7.4 HighN/A1%Sep 21, 2026
CVE-2026-73513: Improper Input Validation7.5 HighN/A1%Sep 21, 2026
CVE-2026-73512: Use After Free7.5 HighN/A1%Sep 21, 2026
CVE-2026-62247: Incorrect Authorization6.5 MediumN/A0%Sep 21, 2026
CVE-2026-58271: Improper Restriction of Excessive Authentication Attempts6.8 MediumN/A0%Sep 21, 2026
CVE-2026-58269: Authentication Bypass Using an Alternate Path or Channel8.1 HighN/A0%Sep 21, 2026
CVE-2026-55897: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A0%Sep 21, 2026
CVE-2026-55159: Improper Neutralization of CRLF Sequences8.8 HighN/A0%Sep 21, 2026
CVE-2026-54915: URL Redirection to Untrusted Site5.4 MediumN/A0%Sep 21, 2026
CVE-2026-52835: Improper Limitation of a Pathname to a Restricted DirectoryN/A7.0 High0%Sep 21, 2026
CVE-2026-50572: Use After Free5.9 MediumN/A1%Sep 21, 2026
CVE-2026-49811: Incorrect Permission Assignment for Critical Resource8.4 HighN/A0%Sep 21, 2026
CVE-2026-48521: NULL Pointer Dereference5.9 MediumN/A1%Sep 21, 2026
CVE-2026-45381: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Sep 21, 2026
CVE-2026-94501: Missing Authorization8.8 High8.7 High0%Sep 21, 2026
CVE-2026-94497: Authorization Bypass Through User-Controlled Key8.3 High8.7 High0%Sep 21, 2026
CVE-2026-94496: Missing Authorization8.3 High8.7 High0%Sep 21, 2026
CVE-2026-94495: Missing Authorization7.1 High7.1 High0%Sep 21, 2026
CVE-2026-94494: Authorization Bypass Through User-Controlled Key5.0 Medium5.3 Medium0%Sep 21, 2026
CVE-2026-94414: Missing Authorization5.4 Medium5.3 Medium0%Sep 21, 2026
CVE-2026-94413: Exposure of Sensitive Information to an Unauthorized Actor6.5 Medium7.1 High0%Sep 21, 2026
CVE-2026-94412: Missing Authorization8.8 High8.7 High0%Sep 21, 2026
CVE-2026-94411: Missing Authorization8.8 High8.7 High0%Sep 21, 2026
CVE-2026-94403: Untrusted Pointer Dereference8.8 High8.5 High0%Sep 21, 2026
1126-1150 of 552652