The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-59686: Improper Neutralization of Special Elements used in an OS Command8.4 HighN/A1%Jul 27, 2026
CVE-2026-56538: Exposure of Sensitive Information Due to Incompatible Policies3.5 LowN/A0%Jul 27, 2026
CVE-2026-56537: Generation of Error Message Containing Sensitive Information3.5 LowN/A0%Jul 27, 2026
CVE-2026-17512: Out-of-bounds Read3.3 Low1.9 Low0%Jul 27, 2026
CVE-2026-12991: Channel Accessible by Non-EndpointN/A8.7 High0%Jul 27, 2026
CVE-2026-12990: Improper Access ControlN/A7.7 High0%Jul 27, 2026
CVE-2026-12989: Missing Authentication for Critical FunctionN/A8.7 High0%Jul 27, 2026
CVE-2026-66053: Improper Validation of Certificate with Host Mismatch5.9 MediumN/A0%Jul 27, 2026
CVE-2026-58662: Improper Validation of Specified Quantity in Input9.1 Critical8.7 High1%Jul 27, 2026
CVE-2026-58389: Allocation of Resources Without Limits or Throttling7.5 High8.7 High1%Jul 27, 2026
CVE-2026-58023: Out-of-bounds Read9.1 Critical6.9 Medium1%Jul 27, 2026
CVE-2026-57917: Improper Restriction of XML External Entity ReferenceN/A4.8 Medium0%Jul 27, 2026
CVE-2026-57916: External Control of File Name or PathN/A4.6 Medium0%Jul 27, 2026
CVE-2026-55971: Heap-based Buffer Overflow9.8 Critical9.3 Critical1%Jul 27, 2026
CVE-2026-55970: Buffer Over-read6.5 Medium6.9 Medium0%Jul 27, 2026
CVE-2026-55969: Integer Overflow or Wraparound7.5 High8.7 High1%Jul 27, 2026
CVE-2026-55968: Inefficient Algorithmic Complexity7.5 High8.7 High1%Jul 27, 2026
CVE-2026-49158: Improper Handling of Highly Compressed Data (Data Amplification)7.5 HighN/A1%Jul 27, 2026
CVE-2026-48586: Improper Handling of Highly Compressed Data (Data Amplification)7.5 High8.7 High1%Jul 27, 2026
CVE-2026-48145: Improper Validation of Certificate with Host Mismatch7.5 High8.2 High0%Jul 27, 2026
CVE-2026-48144: Improper Validation of Certificate with Host Mismatch9.1 Critical9.1 Critical0%Jul 27, 2026
CVE-2026-45112: Allocation of Resources Without Limits or Throttling7.5 High6.9 Medium1%Jul 27, 2026
CVE-2026-43871: Loop with Unreachable Exit Condition7.5 High8.7 High1%Jul 27, 2026
CVE-2026-41608: Improper Handling of Highly Compressed Data (Data Amplification)7.5 HighN/A1%Jul 27, 2026
CVE-2026-14856: Improper Neutralization of Input During Web Page GenerationN/A6.3 Medium0%Jul 27, 2026
26451-26475 of 397021