The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-15240: Improper Authentication7.5 HighN/A0%Jul 30, 2026
CVE-2026-15235: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Jul 30, 2026
CVE-2026-15153: Improper Neutralization of Special Elements used in an SQL Command6.8 MediumN/A0%Jul 30, 2026
CVE-2026-15054: Missing Authorization3.7 LowN/A0%Jul 30, 2026
CVE-2026-14923: Incorrect Authorization6.5 MediumN/A0%Jul 30, 2026
CVE-2026-14602: Improper Control of Generation of Code9.0 CriticalN/A1%Jul 30, 2026
CVE-2026-14592: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 30, 2026
CVE-2026-14318: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Jul 30, 2026
CVE-2026-14310: Authorization Bypass Through User-Controlled Key5.4 MediumN/A0%Jul 30, 2026
CVE-2026-14305: Improper Authentication5.3 MediumN/A0%Jul 30, 2026
CVE-2026-14239: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Jul 30, 2026
CVE-2026-14231: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Jul 30, 2026
CVE-2026-14226: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Jul 30, 2026
CVE-2026-14223: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Jul 30, 2026
CVE-2026-14222: Improper Access Control3.8 LowN/A0%Jul 30, 2026
CVE-2026-14221: Improper Access Control3.8 LowN/A0%Jul 30, 2026
CVE-2026-14207: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 30, 2026
CVE-2026-14188: Exposure of Sensitive Information to an Unauthorized Actor2.7 LowN/A0%Jul 30, 2026
CVE-2026-13395: Improper Neutralization of Special Elements used in an SQL Command8.6 HighN/A0%Jul 30, 2026
CVE-2026-13345: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Jul 30, 2026
CVE-2026-13344: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Jul 30, 2026
CVE-2026-13330: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 30, 2026
CVE-2026-13178: Authorization Bypass Through User-Controlled Key7.5 HighN/A0%Jul 30, 2026
CVE-2026-13145: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Jul 30, 2026
CVE-2026-13143: Authentication Bypass by Spoofing5.3 MediumN/A0%Jul 30, 2026
25651-25675 of 450481