The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-93527: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Sep 23, 2026
CVE-2026-93526: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Sep 23, 2026
CVE-2026-93513: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Sep 23, 2026
CVE-2026-93421: Improper Output Neutralization for LogsN/A5.3 Medium0%Sep 23, 2026
CVE-2026-92730: Improper Neutralization of Input During Web Page GenerationN/A7.4 High0%Sep 23, 2026
CVE-2026-92700: Improper Handling of Case SensitivityN/A6.3 Medium0%Sep 23, 2026
CVE-2026-92692: Improper Neutralization of Special Elements used in an SQL CommandN/A6.9 Medium0%Sep 23, 2026
CVE-2026-92284: Allocation of Resources Without Limits or ThrottlingN/A6.9 Medium0%Sep 23, 2026
CVE-2026-90905: Cross-Site Request Forgery (CSRF)N/A7.2 High0%Sep 23, 2026
CVE-2026-90904: Improper Access ControlN/A8.6 High0%Sep 23, 2026
CVE-2026-90903: Cross-Site Request Forgery (CSRF)N/A7.2 High0%Sep 23, 2026
CVE-2026-90902: Improper Neutralization of Special Elements in Output Used by a Downstream ComponentN/A8.2 High0%Sep 23, 2026
CVE-2026-90901: Improper Neutralization of Special Elements in Output Used by a Downstream ComponentN/A8.6 High0%Sep 23, 2026
CVE-2026-90900: Cross-Site Request Forgery (CSRF)N/A5.3 Medium0%Sep 23, 2026
CVE-2026-90899: Exposure of Sensitive Information to an Unauthorized ActorN/A8.2 High0%Sep 23, 2026
CVE-2026-84502: Improper Neutralization of Argument Delimiters in a Command9.9 CriticalN/A1%Sep 23, 2026
CVE-2026-84499: Generation of Error Message Containing Sensitive Information7.7 HighN/A0%Sep 23, 2026
CVE-2026-84486: Active Debug Code8.2 HighN/A1%Sep 23, 2026
CVE-2026-84474: Reliance on Untrusted Inputs in a Security Decision9.9 CriticalN/A1%Sep 23, 2026
CVE-2026-82368: Improper Access ControlN/A8.7 High0%Sep 23, 2026
CVE-2026-82356: Undefined Security Weakness7.5 HighN/A0%Sep 23, 2026
CVE-2026-77602: Improper Control of Generation of Code9.9 CriticalN/A1%Sep 23, 2026
CVE-2026-77601: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Sep 23, 2026
CVE-2026-77423: Inefficient Regular Expression Complexity7.5 HighN/A0%Sep 23, 2026
CVE-2026-77422: Inefficient Regular Expression Complexity7.5 HighN/A0%Sep 23, 2026
1176-1200 of 430278