The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-26334: Use of Hard-coded Credentials7.8 High8.5 High0%Feb 13, 2026
CVE-2026-2026: Incorrect Default Permissions6.1 Medium5.4 Medium0%Feb 13, 2026
CVE-2025-1790: Execution with Unnecessary PrivilegesN/A5.8 Medium0%Feb 13, 2026
CVE-2026-0872: Improper Certificate ValidationN/A2.5 Low0%Feb 13, 2026
CVE-2020-37181: Stack-based Buffer Overflow9.8 Critical6.7 Medium0%Feb 11, 2026
CVE-2026-0228: Improper Certificate ValidationN/A1.3 Low0%Feb 11, 2026
CVE-2019-25308: Unquoted Search Path or Element7.8 High8.5 High0%Feb 11, 2026
CVE-2019-25307: Unquoted Search Path or Element7.8 High8.5 High0%Feb 11, 2026
CVE-2026-1762: Relative Path Traversal2.9 LowN/A0%Feb 10, 2026
CVE-2026-20846: Buffer Over-read7.5 HighN/A1%Feb 10, 2026
CVE-2026-20841: Improper Neutralization of Special Elements used in a Command7.8 HighN/A12%Feb 10, 2026
CVE-2026-21222: Insertion of Sensitive Information into Log File5.5 MediumN/A1%Feb 10, 2026
CVE-2026-21231: Concurrent Execution using Shared Resource with Improper Synchronization7.8 HighN/A3%Feb 10, 2026
CVE-2026-21232: Untrusted Pointer Dereference7.8 HighN/A0%Feb 10, 2026
CVE-2026-21237: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Feb 10, 2026
CVE-2026-21238: Improper Access Control7.8 HighN/A3%Feb 10, 2026
CVE-2026-21239: Heap-based Buffer Overflow7.8 HighN/A0%Feb 10, 2026
CVE-2026-21241: Use After Free7.0 HighN/A3%Feb 10, 2026
CVE-2026-21240: Time-of-check Time-of-use (TOCTOU) Race Condition7.8 HighN/A0%Feb 10, 2026
CVE-2026-21243: NULL Pointer Dereference7.5 HighN/A1%Feb 10, 2026
CVE-2026-21244: Heap-based Buffer Overflow7.3 HighN/A1%Feb 10, 2026
CVE-2026-21245: Heap-based Buffer Overflow7.8 HighN/A0%Feb 10, 2026
CVE-2026-21249: External Control of File Name or Path3.3 LowN/A11%Feb 10, 2026
CVE-2026-21250: Untrusted Pointer Dereference7.8 HighN/A1%Feb 10, 2026
CVE-2026-21251: Use After Free7.8 HighN/A0%Feb 10, 2026
2501-2525 of 16013