The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-27064: Unrestricted Upload of File with Dangerous Type9.1 CriticalN/A0%Jul 23, 2026
CVE-2026-25466: Missing Authorization5.3 MediumN/A0%Jul 23, 2026
CVE-2026-25427: Missing Authorization5.4 MediumN/A0%Jul 23, 2026
CVE-2026-25424: Missing Authorization4.3 MediumN/A0%Jul 23, 2026
CVE-2026-25405: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Jul 23, 2026
CVE-2026-24639: Server-Side Request Forgery (SSRF)4.4 MediumN/A0%Jul 23, 2026
CVE-2026-24628: Improper Neutralization of Input During Web Page Generation5.9 MediumN/A0%Jul 23, 2026
CVE-2026-24552: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Jul 23, 2026
CVE-2026-24537: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Jul 23, 2026
CVE-2025-68081: Improper Neutralization of Input During Web Page Generation5.9 MediumN/A0%Jul 23, 2026
CVE-2026-64611: Loop with Unreachable Exit Condition7.5 HighN/A0%Jul 23, 2026
CVE-2026-16745: Origin Validation Error8.8 HighN/A0%Jul 23, 2026
CVE-2026-65758: Improper Access ControlN/A8.2 High0%Jul 23, 2026
CVE-2026-65757: Cross-Site Request Forgery (CSRF)8.1 HighN/A0%Jul 23, 2026
CVE-2026-65756: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 23, 2026
CVE-2026-65755: Use of Cache Containing Sensitive Information7.5 HighN/A0%Jul 23, 2026
CVE-2026-65754: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A0%Jul 23, 2026
CVE-2026-65713: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Jul 23, 2026
CVE-2026-65712: Improper Limitation of a Pathname to a Restricted Directory6.2 MediumN/A0%Jul 23, 2026
CVE-2026-65431: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A0%Jul 23, 2026
CVE-2026-65430: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Jul 23, 2026
CVE-2026-64876: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Jul 23, 2026
CVE-2026-64875: Authentication Bypass by Spoofing6.5 MediumN/A0%Jul 23, 2026
CVE-2026-64874: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A0%Jul 23, 2026
CVE-2026-64873: Server-Side Request Forgery (SSRF)9.8 CriticalN/A0%Jul 23, 2026
27301-27325 of 559420