The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-66757: Integer Overflow or Wraparound5.5 MediumN/A0%Jul 27, 2026
CVE-2026-66031: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Jul 27, 2026
CVE-2026-64647: Improper Encoding or Escaping of Output5.4 Medium6.3 Medium0%Jul 27, 2026
CVE-2026-64646: Allocation of Resources Without Limits or Throttling5.3 Medium6.3 Medium1%Jul 27, 2026
CVE-2026-51244: Undefined Security WeaknessN/AN/A0%Jul 27, 2026
CVE-2026-17612: Exposure of Sensitive Information to an Unauthorized ActorN/A6.9 Medium0%Jul 27, 2026
CVE-2026-16481: Server-Side Request Forgery (SSRF)N/A6.0 Medium0%Jul 27, 2026
CVE-2026-12383: Insufficient Verification of Data Authenticity7.5 HighN/A0%Jul 27, 2026
CVE-2026-10683: Loop with Unreachable Exit Condition4.6 MediumN/A0%Jul 27, 2026
CVE-2026-10682: Out-of-bounds Write7.8 HighN/A0%Jul 27, 2026
CVE-2026-66030: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Jul 27, 2026
CVE-2026-66029: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Jul 27, 2026
CVE-2026-66028: Incorrect Implementation of Authentication Algorithm6.7 Medium7.1 High0%Jul 27, 2026
CVE-2026-64645: Server-Side Request Forgery (SSRF)6.1 Medium8.3 High1%Jul 27, 2026
CVE-2026-64644: Inefficient Algorithmic Complexity5.3 Medium6.3 Medium1%Jul 27, 2026
CVE-2026-64643: Insertion of Sensitive Information Into Sent Data5.3 Medium6.3 Medium1%Jul 27, 2026
CVE-2026-64642: Improper Authorization8.2 High8.3 High1%Jul 27, 2026
CVE-2026-64641: Excessive Iteration7.5 High8.2 High1%Jul 27, 2026
CVE-2026-59239: Improper Neutralization of Input During Web Page GenerationN/A8.6 High0%Jul 27, 2026
CVE-2026-55579: Use of Hard-coded Credentials9.8 CriticalN/A1%Jul 27, 2026
CVE-2026-55578: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A0%Jul 27, 2026
CVE-2026-54540: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Jul 27, 2026
CVE-2026-54272: Improper Input ValidationN/A6.9 Medium0%Jul 27, 2026
CVE-2026-51235: Undefined Security WeaknessN/AN/A0%Jul 27, 2026
CVE-2026-48052: Authorization Bypass Through User-Controlled Key5.4 MediumN/A0%Jul 27, 2026
26326-26350 of 552652