The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-13357: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Jul 2, 2026
CVE-2026-11781: Undefined Security Weakness2.7 LowN/A0%Jul 2, 2026
CVE-2026-11578: Undefined Security Weakness2.7 LowN/A0%Jul 2, 2026
CVE-2026-58593: Insufficient Verification of Data Authenticity7.5 High8.7 High0%Jul 1, 2026
CVE-2026-50160: Improperly Controlled Modification of Dynamically-Determined Object Attributes10.0 CriticalN/A2%Jul 1, 2026
CVE-2026-8480: Improper Certificate Validation4.3 MediumN/A0%Jul 1, 2026
CVE-2026-5136: Incorrect Privilege Assignment8.8 HighN/A0%Jul 1, 2026
CVE-2026-53905: Incorrect Authorization7.1 High5.3 Medium0%Jul 1, 2026
CVE-2026-13228: Improper Privilege Management8.8 HighN/A0%Jul 1, 2026
CVE-2026-10095: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 1, 2026
CVE-2026-50043: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High1%Jul 1, 2026
CVE-2026-12224: Improper Privilege Management8.8 HighN/A0%Jul 1, 2026
CVE-2026-12158: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Jul 1, 2026
CVE-2026-11387: Improper Authentication9.8 CriticalN/A0%Jul 1, 2026
CVE-2026-11794: Undefined Security Weakness8.1 HighN/A0%Jul 1, 2026
CVE-2026-7840: Out-of-bounds Write9.8 Critical9.3 Critical1%Jul 1, 2026
CVE-2026-7839: Use of Hard-coded Credentials9.1 CriticalN/A0%Jul 1, 2026
CVE-2026-7829: Out-of-bounds Write7.2 HighN/A1%Jul 1, 2026
CVE-2026-11988: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Jul 1, 2026
CVE-2026-11981: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Jul 1, 2026
CVE-2026-57995: Improper Privilege Management8.8 High8.7 High0%Jun 30, 2026
CVE-2026-56233: Improper Limitation of a Pathname to a Restricted Directory8.3 High8.7 High0%Jun 30, 2026
CVE-2026-37106: Weak Password Recovery Mechanism for Forgotten Password9.8 CriticalN/A1%Jun 30, 2026
CVE-2026-11594: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jun 30, 2026
CVE-2026-11712: Improper Neutralization of Input During Web Page Generation9.3 CriticalN/A0%Jun 30, 2026
2626-2650 of 17489