The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-65765: Improper Limitation of a Pathname to a Restricted DirectoryN/A6.9 Medium0%Jul 27, 2026
CVE-2026-65764: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Jul 27, 2026
CVE-2026-16554: Integer Overflow or WraparoundN/A5.1 Medium0%Jul 27, 2026
CVE-2026-15799: Undefined Security WeaknessN/AN/AN/AJul 27, 2026
CVE-2026-65894: Improper Restriction of Excessive Authentication AttemptsN/A8.7 High0%Jul 27, 2026
CVE-2026-65893: Active Debug CodeN/A7.0 High0%Jul 27, 2026
CVE-2026-64536: Undefined Security Weakness8.1 HighN/A0%Jul 27, 2026
CVE-2026-64535: Undefined Security Weakness9.8 CriticalN/A1%Jul 27, 2026
CVE-2026-64534: Undefined Security Weakness9.8 CriticalN/A0%Jul 27, 2026
CVE-2026-64533: Undefined Security Weakness7.8 HighN/A0%Jul 27, 2026
CVE-2026-64532: Undefined Security Weakness7.8 HighN/A0%Jul 27, 2026
CVE-2026-64531: Undefined Security Weakness7.8 HighN/A0%Jul 27, 2026
CVE-2026-14837: Improper Verification of Cryptographic Signature7.8 High8.5 High0%Jul 27, 2026
CVE-2026-9830: Improper Authentication8.2 HighN/A0%Jul 27, 2026
CVE-2026-66412: Authorization Bypass Through User-Controlled Key6.5 Medium7.1 High0%Jul 27, 2026
CVE-2026-14827: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Jul 27, 2026
CVE-2026-14820: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Jul 27, 2026
CVE-2026-14568: Improper Authentication6.5 MediumN/A0%Jul 27, 2026
CVE-2026-14289: Improper Control of Generation of Code9.0 CriticalN/A0%Jul 27, 2026
CVE-2026-14236: URL Redirection to Untrusted Site4.7 MediumN/A0%Jul 27, 2026
CVE-2026-14235: Improper Access Control7.5 HighN/A0%Jul 27, 2026
CVE-2026-14203: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Jul 27, 2026
CVE-2026-14190: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 27, 2026
CVE-2026-14189: Improper Neutralization of Special Elements used in an SQL Command3.8 LowN/A0%Jul 27, 2026
CVE-2026-13726: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Jul 27, 2026
26476-26500 of 397021