The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-81848: Server-Side Request Forgery (SSRF)3.5 Low5.1 Medium0%Aug 28, 2026
CVE-2026-81847: Improper Limitation of a Pathname to a Restricted Directory5.5 Medium2.0 Low0%Aug 28, 2026
CVE-2026-81845: Improper Limitation of a Pathname to a Restricted Directory6.3 Medium2.1 Low0%Aug 28, 2026
CVE-2026-81837: Improper Limitation of a Pathname to a Restricted Directory6.3 Medium2.1 Low0%Aug 28, 2026
CVE-2026-81836: Cleartext Transmission of Sensitive Information3.7 Low2.9 Low0%Aug 28, 2026
CVE-2026-81835: Improper Control of Generation of Code5.5 Medium2.0 Low0%Aug 28, 2026
CVE-2026-80179: Allocation of Resources Without Limits or Throttling5.9 MediumN/A0%Aug 28, 2026
CVE-2026-78239: Missing Authentication for Critical Function9.8 Critical9.3 Critical1%Aug 28, 2026
CVE-2026-78037: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High1%Aug 28, 2026
CVE-2026-77977: Missing Authentication for Critical Function8.1 High7.2 High0%Aug 28, 2026
CVE-2026-77358: Use After FreeN/A8.2 High0%Aug 28, 2026
CVE-2026-77341: Improper Neutralization of CRLF SequencesN/A5.3 Medium0%Aug 28, 2026
CVE-2026-76945: Use of Client-Side Authentication7.5 High8.7 High0%Aug 28, 2026
CVE-2026-76943: Authentication Bypass Using an Alternate Path or Channel9.8 Critical9.3 Critical1%Aug 28, 2026
CVE-2026-76940: Improper Restriction of Excessive Authentication Attempts7.5 High8.7 High0%Aug 28, 2026
CVE-2026-76179: Use of GET Request Method With Sensitive Query Strings9.8 Critical9.3 Critical0%Aug 28, 2026
CVE-2026-76060: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High2%Aug 28, 2026
CVE-2026-75814: Cross-Site Request Forgery (CSRF)8.8 High8.6 High0%Aug 28, 2026
CVE-2026-75813: Missing Authorization7.5 High8.7 High0%Aug 28, 2026
CVE-2026-75548: Improper Restriction of Rendered UI Layers or Frames5.4 Medium5.3 Medium0%Aug 28, 2026
CVE-2026-75419: Improper Neutralization of CRLF Sequences in HTTP Headers8.8 HighN/A0%Aug 28, 2026
CVE-2026-75418: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Aug 28, 2026
CVE-2026-75417: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Aug 28, 2026
CVE-2026-75339: Missing Authorization8.8 HighN/A0%Aug 28, 2026
CVE-2026-75337: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A0%Aug 28, 2026
12951-12975 of 559420