The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-69264: Improper Control of Generation of Code9.8 Critical9.4 Critical1%Aug 4, 2026
CVE-2026-47763: UNIX Symbolic Link (Symlink) FollowingN/A6.8 Medium0%Aug 4, 2026
CVE-2026-47623: Deserialization of Untrusted Data8.2 HighN/A1%Aug 4, 2026
CVE-2026-47622: Generation of Error Message Containing Sensitive Information5.3 MediumN/A0%Aug 4, 2026
CVE-2026-47621: Time-of-check Time-of-use (TOCTOU) Race Condition6.5 MediumN/A0%Aug 4, 2026
CVE-2026-47620: Concurrent Execution using Shared Resource with Improper Synchronization6.5 MediumN/A0%Aug 4, 2026
CVE-2026-47619: Reliance on Insufficiently Trustworthy Component8.1 HighN/A1%Aug 4, 2026
CVE-2026-47618: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Aug 4, 2026
CVE-2026-47617: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Aug 4, 2026
CVE-2026-47616: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Aug 4, 2026
CVE-2026-47615: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Aug 4, 2026
CVE-2026-47614: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Aug 4, 2026
CVE-2026-47613: Server-Side Request Forgery (SSRF)7.5 HighN/A1%Aug 4, 2026
CVE-2026-47612: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Aug 4, 2026
CVE-2026-47487: Improper Limitation of a Pathname to a Restricted Directory7.1 HighN/A0%Aug 4, 2026
CVE-2026-24255: Incomplete Comparison with Missing Factors7.5 HighN/A1%Aug 4, 2026
CVE-2026-24254: Authentication Bypass Using an Alternate Path or Channel9.8 CriticalN/A1%Aug 4, 2026
CVE-2026-24253: Out-of-bounds Write8.2 HighN/A1%Aug 4, 2026
CVE-2026-18830: Improper Validation of Specified Type of Input8.1 High8.6 High1%Aug 4, 2026
CVE-2026-18790: Out-of-bounds Read3.3 Low1.9 Low0%Aug 4, 2026
CVE-2026-18788: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium1%Aug 4, 2026
CVE-2026-69263: Incomplete List of Disallowed Inputs9.8 Critical8.7 High1%Aug 4, 2026
CVE-2026-69262: Incorrect Authorization8.1 High7.1 High1%Aug 4, 2026
CVE-2026-69259: Improper Control of Generation of Code8.8 High9.4 Critical1%Aug 4, 2026
CVE-2026-69258: Authorization Bypass Through User-Controlled Key9.1 Critical8.8 High1%Aug 4, 2026
25376-25400 of 400317