The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-12687: Improper Privilege Management7.5 HighN/A0%Jul 30, 2026
CVE-2026-12500: Missing Authorization7.5 HighN/A0%Jul 30, 2026
CVE-2026-11881: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 30, 2026
CVE-2026-11870: Authentication Bypass by Spoofing5.4 MediumN/A0%Jul 30, 2026
CVE-2026-11867: Missing Authorization6.5 MediumN/A0%Jul 30, 2026
CVE-2026-11782: Improper Access Control5.9 MediumN/A0%Jul 30, 2026
CVE-2026-67248: Stack-based Buffer Overflow8.8 High8.7 High0%Jul 30, 2026
CVE-2026-67247: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium7.1 High0%Jul 30, 2026
CVE-2026-67246: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium6.9 Medium0%Jul 30, 2026
CVE-2026-67245: Improper Limitation of a Pathname to a Restricted Directory8.1 High7.0 High0%Jul 30, 2026
CVE-2026-1360: Deserialization of Untrusted Data7.5 HighN/A1%Jul 30, 2026
CVE-2026-16610: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Jul 30, 2026
CVE-2026-14356: Missing Authorization8.8 HighN/A0%Jul 30, 2026
CVE-2026-67244: Use of Externally-Controlled Format String7.2 High8.6 High0%Jul 30, 2026
CVE-2026-48449: Incorrect Authorization9.8 CriticalN/A1%Jul 30, 2026
CVE-2026-48448: Improper Neutralization of Special Elements used in an SQL Command8.6 HighN/A1%Jul 30, 2026
CVE-2026-1982: External Control of Assumed-Immutable Web Parameter5.3 MediumN/A0%Jul 30, 2026
CVE-2026-18188: Use of Externally-Controlled Format String8.1 High7.1 High0%Jul 30, 2026
CVE-2026-18187: Use of Externally-Controlled Format String8.1 High7.1 High0%Jul 30, 2026
CVE-2026-18186: Use of Externally-Controlled Format String8.1 High7.1 High0%Jul 30, 2026
CVE-2026-16092: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Jul 30, 2026
CVE-2026-16727: Concurrent Execution using Shared Resource with Improper SynchronizationN/A7.3 High0%Jul 30, 2026
CVE-2026-15929: Improper Neutralization of Special Elements used in an SQL CommandN/A7.1 High0%Jul 30, 2026
CVE-2026-59952: Improper Handling of Exceptional ConditionsN/A6.9 Medium1%Jul 30, 2026
CVE-2026-18019: Improper Protection of Physical Side Channels4.3 MediumN/A0%Jul 30, 2026
25676-25700 of 395490