The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-50007: Missing AuthorizationN/A7.2 High0%Jul 7, 2026
CVE-2026-58468: Server-Side Request Forgery (SSRF)5.5 Medium5.1 Medium0%Jul 7, 2026
CVE-2026-23698: Unrestricted Upload of File with Dangerous Type7.2 High8.6 High1%Jul 7, 2026
CVE-2026-13020: Weak Password Recovery Mechanism for Forgotten Password9.8 CriticalN/A0%Jul 7, 2026
CVE-2026-57851: Exposed IOCTL with Insufficient Access Control7.8 High8.5 High0%Jul 7, 2026
CVE-2026-12948: Improper Neutralization of Input During Web Page GenerationN/A4.8 Medium0%Jul 7, 2026
CVE-2026-6101: External Control of File Name or Path7.5 HighN/A1%Jul 7, 2026
CVE-2026-57869: Authorization Bypass Through User-Controlled KeyN/A7.1 High0%Jul 7, 2026
CVE-2026-14345: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Jul 7, 2026
CVE-2026-12375: Undefined Security Weakness9.8 CriticalN/A0%Jul 7, 2026
CVE-2026-53648: External Control of File Name or PathN/A5.1 Medium0%Jul 7, 2026
CVE-2026-53647: Exposure of Sensitive Information to an Unauthorized ActorN/A6.9 Medium0%Jul 7, 2026
CVE-2026-43925: Improperly Controlled Modification of Dynamically-Determined Object AttributesN/A6.9 Medium0%Jul 6, 2026
CVE-2026-38979: Improper Restriction of Rendered UI Layers or Frames5.4 MediumN/A0%Jul 6, 2026
CVE-2026-42331: Missing Authentication for Critical FunctionN/A7.7 High0%Jul 6, 2026
CVE-2026-33734: Improper Neutralization of Special Elements used in an SQL CommandN/A6.9 Medium0%Jul 6, 2026
CVE-2026-9181: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Jul 6, 2026
CVE-2025-53829: Relative Path Traversal8.0 HighN/A1%Jul 6, 2026
CVE-2025-53828: Server-Side Request Forgery (SSRF)8.5 HighN/A0%Jul 6, 2026
CVE-2025-53827: Exposed Dangerous Method or Function9.1 CriticalN/A1%Jul 6, 2026
CVE-2026-48203: Improper Neutralization of Special Elements in Output Used by a Downstream Component9.1 CriticalN/A0%Jul 6, 2026
CVE-2026-1433: Insufficiently Protected CredentialsN/A4.8 Medium0%Jul 6, 2026
CVE-2026-12083: Undefined Security Weakness8.1 HighN/A0%Jul 6, 2026
CVE-2026-11962: Undefined Security Weakness8.8 HighN/A0%Jul 6, 2026
CVE-2026-11855: Undefined Security Weakness8.8 HighN/A0%Jul 6, 2026
2576-2600 of 17489