The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-68746: Not Failing Securely8.8 High7.7 High0%Aug 5, 2026
CVE-2026-66885: Cross-Site Request Forgery (CSRF)6.5 Medium6.8 Medium0%Aug 5, 2026
CVE-2026-66881: Relative Path Traversal8.1 High7.0 High0%Aug 5, 2026
CVE-2026-66298: Origin Validation Error8.8 High8.6 High0%Aug 5, 2026
CVE-2026-66297: Improper Neutralization of Special Elements used in an OS Command8.0 High5.0 Medium2%Aug 5, 2026
CVE-2026-55524: Time-of-check Time-of-use (TOCTOU) Race Condition7.5 HighN/A0%Aug 5, 2026
CVE-2026-55523: Server-Side Request Forgery (SSRF)N/A7.7 High0%Aug 5, 2026
CVE-2026-55522: Improper Control of Generation of Code7.8 HighN/A0%Aug 5, 2026
CVE-2026-21766: Insufficiently Protected Credentials5.4 MediumN/A0%Aug 5, 2026
CVE-2026-18958: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Aug 5, 2026
CVE-2026-18954: Incorrect Authorization5.5 Medium5.7 Medium0%Aug 5, 2026
CVE-2026-18953: Improper Limitation of a Pathname to a Restricted Directory8.8 High6.3 Medium0%Aug 5, 2026
CVE-2026-17556: Improper Limitation of a Pathname to a Restricted Directory9.1 Critical8.8 High1%Aug 5, 2026
CVE-2026-9205: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)9.8 CriticalN/A0%Aug 5, 2026
CVE-2026-9201: Inadequate Encryption Strength8.8 HighN/A0%Aug 5, 2026
CVE-2026-9196: Improper Control of Generation of Code8.8 HighN/A1%Aug 5, 2026
CVE-2026-9130: Authorization Bypass Through User-Controlled Key7.1 HighN/A0%Aug 5, 2026
CVE-2026-8478: Improper Control of Generation of Code8.8 HighN/A1%Aug 5, 2026
CVE-2026-8470: Use of a Broken or Risky Cryptographic Algorithm9.1 CriticalN/A0%Aug 5, 2026
CVE-2026-8183: Improper Limitation of a Pathname to a Restricted Directory7.7 HighN/A1%Aug 5, 2026
CVE-2026-8182: Improper Control of Generation of Code8.8 HighN/A1%Aug 5, 2026
CVE-2026-7869: Improper Limitation of a Pathname to a Restricted Directory5.4 MediumN/A0%Aug 5, 2026
CVE-2026-7658: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Aug 5, 2026
CVE-2026-70612: Improper Access Control5.4 MediumN/A0%Aug 5, 2026
CVE-2026-63457: Uncontrolled Resource Consumption6.5 MediumN/A0%Aug 5, 2026
24976-25000 of 403401