The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-64259: Use After Free7.8 HighN/A0%Jul 25, 2026
CVE-2026-64258: NULL Pointer Dereference5.5 MediumN/A0%Jul 25, 2026
CVE-2026-64257: Undefined Security Weakness9.1 CriticalN/A1%Jul 25, 2026
CVE-2026-64256: Undefined Security Weakness5.5 MediumN/A0%Jul 25, 2026
CVE-2026-16766: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Jul 25, 2026
CVE-2026-15425: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 25, 2026
CVE-2026-14955: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Jul 25, 2026
CVE-2026-10818: Unrestricted Upload of File with Dangerous Type8.1 HighN/A1%Jul 25, 2026
CVE-2026-66374: Improper Validation of Specified Quantity in Input8.1 HighN/A0%Jul 25, 2026
CVE-2026-66373: Double Free7.5 HighN/A1%Jul 25, 2026
CVE-2026-66339: Insertion of Sensitive Information Into Sent Data6.5 MediumN/A0%Jul 24, 2026
CVE-2026-66338: Inconsistent Interpretation of HTTP Requests7.2 HighN/A0%Jul 24, 2026
CVE-2026-66337: Out-of-bounds Read6.5 MediumN/A0%Jul 24, 2026
CVE-2026-61892: Incorrect Permission Assignment for Critical Resource8.8 High8.7 High0%Jul 24, 2026
CVE-2026-61886: Plaintext Storage of a Password6.5 Medium7.1 High0%Jul 24, 2026
CVE-2026-60135: Incorrect User Management6.5 Medium7.1 High0%Jul 24, 2026
CVE-2026-60134: Reliance on Cookies without Validation and Integrity Checking in a Security Decision8.8 High8.7 High0%Jul 24, 2026
CVE-2026-16280: Integer Overflow or Wraparound9.8 CriticalN/A0%Jul 24, 2026
CVE-2026-61884: Missing Authentication for Critical Function9.8 Critical9.3 Critical0%Jul 24, 2026
CVE-2026-55985: Cleartext Storage of Sensitive Information4.3 Medium5.3 Medium0%Jul 24, 2026
CVE-2025-71408: Improper Neutralization of Directives in Dynamically Evaluated Code7.8 High8.5 High0%Jul 24, 2026
CVE-2026-66041: Out-of-bounds Write7.8 High7.7 High1%Jul 24, 2026
CVE-2026-66040: Heap-based Buffer Overflow8.8 High8.7 High1%Jul 24, 2026
CVE-2026-66039: Integer Overflow or Wraparound7.8 High8.7 High0%Jul 24, 2026
CVE-2026-66038: Use of Uninitialized Resource6.5 Medium7.1 High0%Jul 24, 2026
26751-26775 of 395809