The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-55390: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Jul 28, 2026
CVE-2026-55389: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Jul 28, 2026
CVE-2026-54691: Server-Side Request Forgery (SSRF)8.2 HighN/A0%Jul 28, 2026
CVE-2026-54690: Server-Side Request Forgery (SSRF)8.2 HighN/A0%Jul 28, 2026
CVE-2026-54656: Improper Control of Generation of Code7.8 HighN/A0%Jul 28, 2026
CVE-2026-54655: Improper Control of Generation of Code7.8 HighN/A0%Jul 28, 2026
CVE-2026-54654: Improper Control of Generation of Code7.8 HighN/A0%Jul 28, 2026
CVE-2026-54653: Improper Control of Generation of Code8.8 HighN/A0%Jul 28, 2026
CVE-2026-54621: Improper Control of Generation of Code7.8 HighN/A0%Jul 28, 2026
CVE-2026-6881: Improper Neutralization of Special Elements used in an SQL CommandN/A9.4 Critical0%Jul 28, 2026
CVE-2026-59943: Generation of Error Message Containing Sensitive Information5.3 Medium6.3 Medium0%Jul 28, 2026
CVE-2026-59942: Uncontrolled Resource Consumption7.5 High6.3 Medium1%Jul 28, 2026
CVE-2026-59941: Uncontrolled Resource Consumption7.5 High6.3 Medium1%Jul 28, 2026
CVE-2026-56722: Improper Input Validation5.3 Medium6.3 Medium0%Jul 28, 2026
CVE-2026-49447: Improper Authentication5.3 MediumN/A0%Jul 28, 2026
CVE-2026-16581: Inclusion of Sensitive Information in Source Code5.3 Medium6.9 Medium0%Jul 28, 2026
CVE-2026-15328: Inconsistent Interpretation of HTTP Requests8.1 HighN/A0%Jul 28, 2026
CVE-2026-15325: Inconsistent Interpretation of HTTP Requests8.7 HighN/A0%Jul 28, 2026
CVE-2026-15280: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Jul 28, 2026
CVE-2026-15064: Inconsistent Interpretation of HTTP Requests8.7 HighN/A0%Jul 28, 2026
CVE-2026-15057: Out-of-bounds Write7.5 HighN/A0%Jul 28, 2026
CVE-2026-14996: Insufficient Session Expiration8.2 HighN/A0%Jul 28, 2026
CVE-2026-14981: Uncontrolled Resource Consumption7.5 HighN/A0%Jul 28, 2026
CVE-2026-14976: Missing Authentication for Critical Function9.8 CriticalN/A0%Jul 28, 2026
CVE-2026-14974: Deserialization of Untrusted Data9.8 CriticalN/A0%Jul 28, 2026
26201-26225 of 552652