The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-44955: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 Medium6.9 Medium0%Jul 23, 2026
CVE-2026-42933: Unintended Proxy or Intermediary10.0 Critical10.0 Critical1%Jul 23, 2026
CVE-2026-40430: Plaintext Storage of a Password7.5 High8.7 High0%Jul 23, 2026
CVE-2026-28698: Exposure of Sensitive System Information to an Unauthorized Control Sphere8.6 High9.2 Critical0%Jul 23, 2026
CVE-2026-16767: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium5.5 Medium1%Jul 23, 2026
CVE-2026-65694: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High3%Jul 23, 2026
CVE-2026-65604: Improper Input Validation8.2 High8.8 High0%Jul 23, 2026
CVE-2026-63732: Improper Neutralization of Special Elements used in an OS Command9.9 Critical9.4 Critical1%Jul 23, 2026
CVE-2026-63313: Server-Side Request Forgery (SSRF)7.7 High8.3 High0%Jul 23, 2026
CVE-2026-16807: Out-of-bounds Write8.8 HighN/A0%Jul 23, 2026
CVE-2026-16806: Use After Free8.8 HighN/A0%Jul 23, 2026
CVE-2026-16805: Use After Free8.8 HighN/A0%Jul 23, 2026
CVE-2026-16804: Use After Free8.3 HighN/A0%Jul 23, 2026
CVE-2026-16765: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Jul 23, 2026
CVE-2026-16764: Improper Privilege Management6.3 Medium2.1 Low0%Jul 23, 2026
CVE-2026-16763: Improper Neutralization of Special Elements used in an OS Command5.3 Medium1.9 Low1%Jul 23, 2026
CVE-2025-71389: Improper Control of Generation of Code10.0 Critical10.0 Critical1%Jul 23, 2026
CVE-2024-58355: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)8.9 High9.3 Critical0%Jul 23, 2026
CVE-2024-58354: Improper Neutralization of Special Elements used in a Command9.9 Critical8.5 High1%Jul 23, 2026
CVE-2024-58353: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)8.9 High9.3 Critical0%Jul 23, 2026
CVE-2026-6924: Same Seed in Pseudo-Random Number Generator (PRNG)N/A8.7 High0%Jul 23, 2026
CVE-2026-52439: Improper Neutralization of Special Elements used in an Expression Language Statement9.8 CriticalN/A1%Jul 23, 2026
CVE-2026-50103: Improper Handling of Syntactically Invalid Structure6.5 Medium7.1 High0%Jul 23, 2026
CVE-2026-50039: Stack-based Buffer Overflow7.5 High8.7 High0%Jul 23, 2026
CVE-2026-50032: NULL Pointer Dereference7.5 High8.7 High0%Jul 23, 2026
26876-26900 of 395809