The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-25039: Uncontrolled Resource Consumption7.5 HighN/A0%Jul 30, 2026
CVE-2026-9322: Uncontrolled Resource Consumption7.5 HighN/A1%Jul 30, 2026
CVE-2026-62663: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Jul 30, 2026
CVE-2026-54722: Improper Neutralization of Equivalent Special ElementsN/A8.7 High1%Jul 30, 2026
CVE-2026-54522: Use After Free5.4 Medium2.1 Low0%Jul 30, 2026
CVE-2026-51295: Undefined Security WeaknessN/AN/A0%Jul 30, 2026
CVE-2026-51294: Undefined Security WeaknessN/AN/A0%Jul 30, 2026
CVE-2026-51293: Undefined Security WeaknessN/AN/A0%Jul 30, 2026
CVE-2026-51292: Undefined Security WeaknessN/AN/A0%Jul 30, 2026
CVE-2026-51291: Undefined Security WeaknessN/AN/A0%Jul 30, 2026
CVE-2026-51290: Undefined Security WeaknessN/AN/A0%Jul 30, 2026
CVE-2026-13379: Improper Neutralization of Value Delimiters9.1 Critical5.1 Medium0%Jul 30, 2026
CVE-2026-12996: Use After Free8.1 High6.0 Medium0%Jul 30, 2026
CVE-2026-12945: Authorization Bypass Through User-Controlled Key7.1 HighN/A0%Jul 30, 2026
CVE-2026-12940: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Jul 30, 2026
CVE-2026-11885: Buffer Copy without Checking Size of Input8.4 HighN/A0%Jul 30, 2026
CVE-2026-11771: Off-by-one Error7.5 High7.0 High0%Jul 30, 2026
CVE-2026-66416: Cross-Site Request Forgery (CSRF)8.8 High8.6 High0%Jul 30, 2026
CVE-2026-66415: Server-Side Request Forgery (SSRF)8.5 High8.4 High0%Jul 30, 2026
CVE-2026-12932: Missing Release of Memory after Effective LifetimeN/A7.1 High0%Jul 30, 2026
CVE-2026-66414: URL Redirection to Untrusted Site6.1 Medium5.1 Medium0%Jul 30, 2026
CVE-2026-13117: Use After FreeN/A6.0 Medium0%Jul 30, 2026
CVE-2026-67596: Weak Encoding for Password6.2 Medium6.9 Medium0%Jul 30, 2026
CVE-2026-58222: Improper Neutralization of Special Elements used in an LDAP Query8.8 HighN/A1%Jul 30, 2026
CVE-2026-58216: Out-of-bounds Read5.3 MediumN/A0%Jul 30, 2026
25501-25525 of 434295