The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-54081: Improperly Controlled Sequential Memory AllocationN/A6.9 Medium0%Jul 29, 2026
CVE-2026-54080: Improperly Controlled Sequential Memory AllocationN/A6.9 Medium0%Jul 29, 2026
CVE-2026-54079: Improper Restriction of XML External Entity ReferenceN/A8.7 High0%Jul 29, 2026
CVE-2026-54078: Improper Restriction of XML External Entity ReferenceN/A8.7 High0%Jul 29, 2026
CVE-2026-50558: Improper Limitation of a Pathname to a Restricted Directory5.9 MediumN/A0%Jul 29, 2026
CVE-2026-17550: Out-of-bounds Read5.5 MediumN/A0%Jul 29, 2026
CVE-2026-16543: Missing AuthorizationN/A7.1 High0%Jul 29, 2026
CVE-2026-16465: Out-of-bounds Read7.1 HighN/A0%Jul 29, 2026
CVE-2026-16463: Heap-based Buffer Overflow7.8 HighN/A0%Jul 29, 2026
CVE-2026-15228: Missing AuthorizationN/A7.1 High0%Jul 29, 2026
CVE-2026-66724: Missing AuthorizationN/A5.3 Medium0%Jul 29, 2026
CVE-2026-66723: Missing AuthorizationN/A7.0 High0%Jul 29, 2026
CVE-2026-65947: Cross-Site Request Forgery (CSRF)7.3 HighN/A0%Jul 29, 2026
CVE-2026-65888: Improper Access Control9.8 Critical10.0 Critical0%Jul 29, 2026
CVE-2026-65887: Improper Access Control9.8 Critical10.0 Critical0%Jul 29, 2026
CVE-2026-65886: Improper Limitation of a Pathname to a Restricted Directory7.5 High9.2 Critical0%Jul 29, 2026
CVE-2026-54666: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.3 HighN/A0%Jul 29, 2026
CVE-2026-54664: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.3 HighN/A0%Jul 29, 2026
CVE-2026-54663: Improper Input Validation6.1 MediumN/A0%Jul 29, 2026
CVE-2026-54662: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.3 HighN/A0%Jul 29, 2026
CVE-2026-54661: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.3 HighN/A0%Jul 29, 2026
CVE-2026-54660: Exposure of Sensitive Information to an Unauthorized Actor7.4 HighN/A0%Jul 29, 2026
CVE-2026-12703: Authentication Bypass Using an Alternate Path or Channel8.0 HighN/A0%Jul 29, 2026
CVE-2026-59247: Insufficient Verification of Data AuthenticityN/A7.6 High0%Jul 29, 2026
CVE-2026-9177: Improper Neutralization of Special Elements Used in a Template EngineN/A9.4 Critical0%Jul 29, 2026
26101-26125 of 400062