The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-43673: Improper Restriction of Operations within the Bounds of a Memory Buffer7.8 HighN/A0%Jul 27, 2026
CVE-2026-43672: Incorrect Authorization7.1 HighN/A0%Jul 27, 2026
CVE-2026-43665: Missing Authorization5.5 MediumN/A0%Jul 27, 2026
CVE-2026-39877: Improper Restriction of Operations within the Bounds of a Memory Buffer7.8 HighN/A0%Jul 27, 2026
CVE-2026-39875: Incorrect Default Permissions7.8 HighN/A0%Jul 27, 2026
CVE-2026-39874: Incorrect Default Permissions7.8 HighN/A0%Jul 27, 2026
CVE-2026-39873: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A1%Jul 27, 2026
CVE-2026-28982: Concurrent Execution using Shared Resource with Improper Synchronization9.8 CriticalN/A0%Jul 27, 2026
CVE-2026-28981: Buffer Copy without Checking Size of Input7.8 HighN/A0%Jul 27, 2026
CVE-2026-28973: Integer Overflow or Wraparound8.6 HighN/A0%Jul 27, 2026
CVE-2026-28945: Improper Access Control7.1 HighN/A0%Jul 27, 2026
CVE-2026-28932: Uncontrolled Resource Consumption5.5 MediumN/A0%Jul 27, 2026
CVE-2026-28931: Buffer Copy without Checking Size of Input8.8 HighN/A0%Jul 27, 2026
CVE-2026-28928: Use After Free9.8 CriticalN/A1%Jul 27, 2026
CVE-2026-28926: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Jul 27, 2026
CVE-2026-28912: Protection Mechanism Failure7.8 HighN/A0%Jul 27, 2026
CVE-2026-28911: Improper Restriction of Operations within the Bounds of a Memory Buffer9.8 CriticalN/A0%Jul 27, 2026
CVE-2026-28900: Authentication Bypass by Spoofing5.5 MediumN/A0%Jul 27, 2026
CVE-2026-28896: Improper Restriction of Operations within the Bounds of a Memory Buffer7.7 HighN/A0%Jul 27, 2026
CVE-2026-28849: Authentication Bypass by Spoofing5.5 MediumN/A0%Jul 27, 2026
CVE-2026-20672: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Jul 27, 2026
CVE-2026-12001: Use of Hard-coded CredentialsN/A5.2 Medium0%Jul 27, 2026
CVE-2026-66018: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Jul 27, 2026
CVE-2026-66015: Improper Privilege Management7.2 HighN/A1%Jul 27, 2026
CVE-2026-66014: Improper Authentication8.8 HighN/A1%Jul 27, 2026
26301-26325 of 552652