The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-93367: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Oct 2, 2026
CVE-2026-14378: Improper Authentication9.8 CriticalN/A0%Oct 2, 2026
CVE-2026-71542: Improper Neutralization of Input During Web Page GenerationN/A8.7 High0%Oct 1, 2026
CVE-2026-70650: Improper Neutralization of Input During Web Page GenerationN/A8.8 High0%Oct 1, 2026
CVE-2026-56662: Cross-Site Request Forgery (CSRF)9.6 CriticalN/A0%Oct 1, 2026
CVE-2026-53953: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)9.1 CriticalN/A0%Oct 1, 2026
CVE-2026-55230: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Oct 1, 2026
CVE-2026-102369: Improper AuthenticationN/A8.7 High0%Oct 1, 2026
CVE-2026-102294: Improper Neutralization of Special Elements used in an OS CommandN/A8.5 High1%Oct 1, 2026
CVE-2026-101890: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Oct 1, 2026
CVE-2026-101889: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium7.0 High0%Oct 1, 2026
CVE-2026-101888: Improper Limitation of a Pathname to a Restricted Directory7.2 High8.6 High1%Oct 1, 2026
CVE-2026-79898: Improper Neutralization of Special Elements used in an OS Command9.1 CriticalN/A1%Oct 1, 2026
CVE-2026-67104: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Oct 1, 2026
CVE-2026-103283: Insufficient Session Expiration8.1 High8.6 High0%Oct 1, 2026
CVE-2026-103277: Improper Neutralization of Input During Web Page Generation8.1 High8.6 High0%Oct 1, 2026
CVE-2026-103255: External Control of File Name or Path9.0 Critical7.1 High0%Oct 1, 2026
CVE-2026-103244: Missing Authentication for Critical Function9.8 Critical9.3 Critical1%Oct 1, 2026
CVE-2026-64946: Improper Neutralization of Input During Web Page GenerationN/A7.4 High0%Oct 1, 2026
CVE-2026-34190: Cross-Site Request Forgery (CSRF)N/A5.9 Medium0%Oct 1, 2026
CVE-2026-34189: Cross-Site Request Forgery (CSRF)N/A5.9 Medium0%Oct 1, 2026
CVE-2026-95687: Improper Privilege Management8.8 HighN/A0%Oct 1, 2026
CVE-2026-89427: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 1, 2026
CVE-2026-85235: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Oct 1, 2026
CVE-2026-103662: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Oct 1, 2026
126-150 of 17411