The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-53431: Authentication Bypass by Capture-replayN/A9.1 Critical1%Jul 30, 2026
CVE-2026-41187: Improper Authorization6.5 Medium6.2 Medium0%Jul 30, 2026
CVE-2026-41186: Active Debug Code7.5 High6.0 Medium1%Jul 30, 2026
CVE-2026-16308: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Jul 30, 2026
CVE-2026-15435: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A1%Jul 30, 2026
CVE-2026-14980: Improper Privilege Management8.8 HighN/A0%Jul 30, 2026
CVE-2026-14522: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Jul 30, 2026
CVE-2026-14519: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Jul 30, 2026
CVE-2026-12947: Insertion of Sensitive Information into Log File7.5 HighN/A0%Jul 30, 2026
CVE-2026-11980: Use of Inherently Dangerous Function7.3 HighN/A0%Jul 30, 2026
CVE-2026-11897: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Jul 30, 2026
CVE-2026-11707: Improper Neutralization of Input During Web Page Generation9.3 CriticalN/A0%Jul 30, 2026
CVE-2026-11383: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Jul 30, 2026
CVE-2025-36431: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Jul 30, 2026
CVE-2025-36298: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Jul 30, 2026
CVE-2026-67351: Missing Critical Step in Authentication8.8 High8.7 High1%Jul 30, 2026
CVE-2026-60075: Inefficient Regular Expression Complexity7.5 HighN/A1%Jul 30, 2026
CVE-2026-60074: Improper Validation of Unsafe Equivalence in Input7.5 HighN/A1%Jul 30, 2026
CVE-2026-5219: Cross-Site Request Forgery (CSRF)8.3 HighN/A0%Jul 30, 2026
CVE-2026-58218: Insufficient Resource Pool5.3 MediumN/A1%Jul 30, 2026
CVE-2026-57859: Deserialization of Untrusted Data7.5 High7.7 High1%Jul 30, 2026
CVE-2026-56428: Incorrect User Management8.1 HighN/A0%Jul 30, 2026
CVE-2026-41709: Insufficient Logging2.7 LowN/A0%Jul 30, 2026
CVE-2026-12722: Missing Authentication for Critical Function8.2 HighN/A0%Jul 30, 2026
CVE-2026-59309: Incorrect Implementation of Authentication Algorithm9.8 CriticalN/A1%Jul 30, 2026
25551-25575 of 430874