The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-64560: Undefined Security Weakness7.8 HighN/A0%Jul 29, 2026
CVE-2026-64559: Undefined Security Weakness7.8 HighN/A0%Jul 29, 2026
CVE-2026-64558: Undefined Security Weakness7.8 HighN/A0%Jul 29, 2026
CVE-2026-54727: Exposure of Resource to Wrong Sphere8.2 HighN/A0%Jul 29, 2026
CVE-2026-54693: Incorrect AuthorizationN/A8.2 High0%Jul 29, 2026
CVE-2026-54680: Improper Neutralization of Special Elements in Output Used by a Downstream Component9.9 CriticalN/A1%Jul 29, 2026
CVE-2026-54574: UNIX Symbolic Link (Symlink) Following8.2 HighN/A0%Jul 29, 2026
CVE-2026-52791: Incorrect Privilege AssignmentN/A2.0 Low0%Jul 29, 2026
CVE-2026-51992: Undefined Security WeaknessN/AN/A1%Jul 29, 2026
CVE-2026-20316: Use of Hard-coded Password5.3 MediumN/A11%Jul 29, 2026
CVE-2026-18257: Improper Certificate Validation5.6 MediumN/A0%Jul 29, 2026
CVE-2026-18255: Incorrect Authorization7.2 HighN/A0%Jul 29, 2026
CVE-2026-16729: Improper Neutralization of Special Elements in Output Used by a Downstream Component6.5 MediumN/A0%Jul 29, 2026
CVE-2026-15144: Improper Restriction of Excessive Authentication Attempts5.3 MediumN/A0%Jul 29, 2026
CVE-2026-13697: Exposure of Sensitive Information to an Unauthorized Actor9.1 CriticalN/A0%Jul 29, 2026
CVE-2025-60931: Authorization Bypass Through User-Controlled Key7.5 HighN/A0%Jul 29, 2026
CVE-2026-67193: Observable Discrepancy5.3 Medium6.9 Medium0%Jul 29, 2026
CVE-2026-67192: Stack-based Buffer Overflow8.1 High9.2 Critical1%Jul 29, 2026
CVE-2026-67191: Heap-based Buffer Overflow9.8 Critical9.3 Critical1%Jul 29, 2026
CVE-2026-67188: Undefined Security WeaknessN/AN/AN/AJul 29, 2026
CVE-2026-66051: Undefined Security WeaknessN/AN/AN/AJul 29, 2026
CVE-2026-60113: Missing Authentication for Critical Function9.8 Critical9.3 Critical1%Jul 29, 2026
CVE-2026-60112: Missing Authentication for Critical Function9.8 Critical9.3 Critical1%Jul 29, 2026
CVE-2026-54735: Server-Side Request Forgery (SSRF)10.0 CriticalN/A0%Jul 29, 2026
CVE-2026-54082: Improper Restriction of XML External Entity Reference6.5 MediumN/A0%Jul 29, 2026
26076-26100 of 544242