The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-67591: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Aug 5, 2026
CVE-2026-67590: Uncontrolled Recursion7.5 HighN/A0%Aug 5, 2026
CVE-2026-67555: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Aug 5, 2026
CVE-2026-67554: Unchecked Input for Loop Condition6.5 MediumN/A0%Aug 5, 2026
CVE-2026-67553: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Aug 5, 2026
CVE-2026-67552: Uncontrolled Recursion7.5 HighN/A0%Aug 5, 2026
CVE-2026-66277: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Aug 5, 2026
CVE-2026-66276: Unchecked Input for Loop Condition6.5 MediumN/A0%Aug 5, 2026
CVE-2026-66275: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Aug 5, 2026
CVE-2026-66274: Uncontrolled Recursion7.5 HighN/A0%Aug 5, 2026
CVE-2026-49004: Improper Neutralization of Special Elements used in an SQL Command6.5 Medium10.0 Critical1%Aug 5, 2026
CVE-2026-17515: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Aug 5, 2026
CVE-2026-16993: Exposure of Sensitive Information to an Unauthorized Actor3.7 LowN/A0%Aug 5, 2026
CVE-2026-16981: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Aug 5, 2026
CVE-2026-16968: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 5, 2026
CVE-2026-16942: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Aug 5, 2026
CVE-2026-16940: Improper Limitation of a Pathname to a Restricted Directory10.0 CriticalN/A0%Aug 5, 2026
CVE-2026-16746: Authorization Bypass Through User-Controlled Key2.7 LowN/A0%Aug 5, 2026
CVE-2026-16736: Improper Access Control7.5 HighN/A0%Aug 5, 2026
CVE-2026-16613: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Aug 5, 2026
CVE-2026-16605: Missing Authorization7.2 HighN/A0%Aug 5, 2026
CVE-2026-16604: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 5, 2026
CVE-2026-16603: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 5, 2026
CVE-2026-16602: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 5, 2026
CVE-2026-16583: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Aug 5, 2026
25226-25250 of 400966