The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-12586: Improper Authentication8.1 HighN/A0%Aug 2, 2026
CVE-2026-11872: Improper Access Control4.3 MediumN/A0%Aug 2, 2026
CVE-2025-15675: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Aug 2, 2026
CVE-2026-9335: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Aug 2, 2026
CVE-2026-8457: Authentication Bypass by Alternate Name9.8 CriticalN/A0%Aug 2, 2026
CVE-2026-18352: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Aug 2, 2026
CVE-2026-13339: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Aug 2, 2026
CVE-2026-17002: Undefined Security WeaknessN/AN/AN/AAug 1, 2026
CVE-2026-18556: Authentication Bypass Using an Alternate Path or Channel7.4 High8.2 High0%Aug 1, 2026
CVE-2026-55735: Improper Verification of Cryptographic Signature7.5 High8.2 High0%Aug 1, 2026
CVE-2026-55734: Allocation of Resources Without Limits or Throttling7.5 High6.9 Medium0%Aug 1, 2026
CVE-2026-55733: Allocation of Resources Without Limits or Throttling7.5 High6.9 Medium0%Aug 1, 2026
CVE-2026-54894: Allocation of Resources Without Limits or Throttling7.5 High6.9 Medium0%Aug 1, 2026
CVE-2026-67355: Insertion of Sensitive Information Into Sent Data5.9 Medium8.2 High0%Aug 1, 2026
CVE-2026-67354: Insertion of Sensitive Information Into Sent Data5.9 Medium8.2 High0%Aug 1, 2026
CVE-2026-67353: Allocation of Resources Without Limits or Throttling5.3 Medium6.9 Medium0%Aug 1, 2026
CVE-2026-67352: Improper Neutralization of Input During Web Page Generation7.6 High6.8 Medium0%Aug 1, 2026
CVE-2026-67344: Missing Authorization4.3 Medium8.5 High0%Aug 1, 2026
CVE-2026-67343: Exposure of Sensitive Information to an Unauthorized Actor8.8 High8.7 High0%Aug 1, 2026
CVE-2026-67342: Authorization Bypass Through User-Controlled Key9.8 Critical9.3 Critical0%Aug 1, 2026
CVE-2026-67341: Incorrect Authorization9.8 Critical9.3 Critical0%Aug 1, 2026
CVE-2026-67340: Improper Control of Generation of Code7.2 High8.6 High1%Aug 1, 2026
CVE-2026-67339: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium6.9 Medium0%Aug 1, 2026
CVE-2026-67338: Improper Neutralization of Encoded URI Schemes in a Web Page6.1 Medium5.1 Medium0%Aug 1, 2026
CVE-2026-67337: Authentication Bypass Using an Alternate Path or Channel6.5 Medium7.1 High0%Aug 1, 2026
25426-25450 of 430277