The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-65535: Exposure of Sensitive System Information to an Unauthorized Control Sphere4.3 MediumN/A0%Jul 23, 2026
CVE-2026-65534: Improper Neutralization of Input During Web Page Generation5.9 MediumN/A0%Jul 23, 2026
CVE-2026-65533: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65532: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Jul 23, 2026
CVE-2026-65531: Missing Authorization4.8 MediumN/A0%Jul 23, 2026
CVE-2026-65530: Missing Authorization4.3 MediumN/A0%Jul 23, 2026
CVE-2026-65529: Missing Authorization5.3 MediumN/A0%Jul 23, 2026
CVE-2026-65528: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65527: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65526: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Jul 23, 2026
CVE-2026-65525: Missing Authorization5.3 MediumN/A0%Jul 23, 2026
CVE-2026-65524: Missing Authorization4.3 MediumN/A0%Jul 23, 2026
CVE-2026-65522: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65521: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Jul 23, 2026
CVE-2026-65519: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65518: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65516: Server-Side Request Forgery (SSRF)7.2 HighN/A0%Jul 23, 2026
CVE-2026-65514: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65512: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Jul 23, 2026
CVE-2026-65511: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Jul 23, 2026
CVE-2026-65510: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Jul 23, 2026
CVE-2026-65506: Missing Authorization5.3 MediumN/A0%Jul 23, 2026
CVE-2026-65505: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Jul 23, 2026
CVE-2026-65503: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65501: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Jul 23, 2026
27101-27125 of 395809