The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-17570: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Jul 27, 2026
CVE-2026-17569: Insufficiently Protected Credentials4.3 MediumN/A0%Jul 27, 2026
CVE-2026-17568: Incorrect Authorization8.8 HighN/A0%Jul 27, 2026
CVE-2026-17552: Server-Side Request Forgery (SSRF)9.1 CriticalN/A0%Jul 27, 2026
CVE-2026-66731: Out-of-bounds Read7.5 High8.7 High1%Jul 27, 2026
CVE-2026-66730: Loop with Unreachable Exit Condition7.5 High8.7 High1%Jul 27, 2026
CVE-2026-66729: Out-of-bounds Read7.5 High8.7 High1%Jul 27, 2026
CVE-2026-66391: Use of Insufficiently Random Values6.5 MediumN/A0%Jul 27, 2026
CVE-2026-66390: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 27, 2026
CVE-2026-24252: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A1%Jul 27, 2026
CVE-2026-17531: Authorization Bypass Through User-Controlled Key5.0 Medium1.3 Low0%Jul 27, 2026
CVE-2026-17192: Server-Side Request Forgery (SSRF)8.5 High6.3 Medium2%Jul 27, 2026
CVE-2026-17191: Improper Neutralization of Special Elements used in an SQL Command9.1 Critical8.5 High3%Jul 27, 2026
CVE-2026-63077: Deserialization of Untrusted Data9.8 CriticalN/A87%Jul 27, 2026
CVE-2026-66399: Improper Privilege Management6.5 Medium8.5 High0%Jul 27, 2026
CVE-2026-66398: Download of Code Without Integrity CheckN/A9.4 Critical0%Jul 27, 2026
CVE-2026-66397: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.6 High0%Jul 27, 2026
CVE-2026-66396: Improper Neutralization of Input During Web Page Generation8.4 High9.3 Critical0%Jul 27, 2026
CVE-2026-66395: Improper Neutralization of Input During Web Page Generation9.6 Critical9.4 Critical0%Jul 27, 2026
CVE-2026-66394: Improper Neutralization of Input During Web Page Generation8.7 High9.3 Critical0%Jul 27, 2026
CVE-2026-59251: Allocation of Resources Without Limits or Throttling7.5 High8.7 High0%Jul 27, 2026
CVE-2026-58227: Uncontrolled Recursion7.5 High8.7 High0%Jul 27, 2026
CVE-2026-55737: Signed to Unsigned Conversion Error7.5 High5.1 Medium0%Jul 27, 2026
CVE-2026-54890: Integer Underflow (Wrap or Wraparound)7.5 High8.2 High0%Jul 27, 2026
CVE-2026-51304: Undefined Security WeaknessN/AN/A0%Jul 27, 2026
26351-26375 of 552652