The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-54368: Improper Neutralization of Special Elements used in an SQL Command8.8 High8.7 High1%Jul 30, 2026
CVE-2026-54367: Missing Authentication for Critical Function8.6 High8.8 High0%Jul 30, 2026
CVE-2026-54366: Improper Restriction of XML External Entity Reference7.5 High8.7 High0%Jul 30, 2026
CVE-2026-54365: Missing Authentication for Critical Function7.5 High8.7 High0%Jul 30, 2026
CVE-2026-54364: Improper Encoding or Escaping of Output6.5 Medium6.9 Medium0%Jul 30, 2026
CVE-2026-54363: Use of Hard-coded Cryptographic Key9.1 Critical9.3 Critical1%Jul 30, 2026
CVE-2026-47876: Out-of-bounds Write9.3 CriticalN/A0%Jul 30, 2026
CVE-2026-41703: Out-of-bounds Read7.6 HighN/A0%Jul 30, 2026
CVE-2026-59310: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A3%Jul 30, 2026
CVE-2026-7260: Stack-based Buffer Overflow5.5 Medium5.4 Medium0%Jul 30, 2026
CVE-2026-5582: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Jul 30, 2026
CVE-2026-18382: Server-Side Request Forgery (SSRF)6.8 MediumN/A0%Jul 30, 2026
CVE-2026-18381: Server-Side Request Forgery (SSRF)7.6 HighN/A0%Jul 30, 2026
CVE-2026-18378: Server-Side Request Forgery (SSRF)6.8 MediumN/A0%Jul 30, 2026
CVE-2026-17544: Out-of-bounds Write9.8 Critical8.1 High0%Jul 30, 2026
CVE-2026-17543: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical8.1 High0%Jul 30, 2026
CVE-2026-15397: Missing Authorization7.2 HighN/A1%Jul 30, 2026
CVE-2026-22622: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Jul 30, 2026
CVE-2026-22621: Improper Neutralization of Special Elements used in an OS Command8.3 HighN/A1%Jul 30, 2026
CVE-2026-22620: Improper Neutralization of Special Elements used in an SQL Command8.6 HighN/A1%Jul 30, 2026
CVE-2026-18369: Server-Side Request Forgery (SSRF)5.8 MediumN/A0%Jul 30, 2026
CVE-2026-18363: Weak Password Recovery Mechanism for Forgotten PasswordN/A9.1 Critical0%Jul 30, 2026
CVE-2026-18362: Allocation of Resources Without Limits or Throttling5.9 MediumN/A0%Jul 30, 2026
CVE-2026-18361: Improper Neutralization of Input During Web Page Generation7.6 HighN/A0%Jul 30, 2026
CVE-2026-18360: Improper Neutralization of Input During Web Page Generation7.6 HighN/A0%Jul 30, 2026
25576-25600 of 433959