The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-64872: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Jul 23, 2026
CVE-2026-64871: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Jul 23, 2026
CVE-2026-64799: Server-Side Request Forgery (SSRF)7.5 HighN/A0%Jul 23, 2026
CVE-2026-16078: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Jul 23, 2026
CVE-2026-15906: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Jul 23, 2026
CVE-2026-15827: Missing Authorization5.3 MediumN/A1%Jul 23, 2026
CVE-2026-15794: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 23, 2026
CVE-2026-15786: Improper Limitation of a Pathname to a Restricted Directory4.4 MediumN/A0%Jul 23, 2026
CVE-2026-15761: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Jul 23, 2026
CVE-2026-15647: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%Jul 23, 2026
CVE-2026-15646: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 23, 2026
CVE-2026-15448: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Jul 23, 2026
CVE-2026-15404: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 23, 2026
CVE-2026-15394: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 23, 2026
CVE-2026-15348: Improper Authentication6.3 MediumN/A1%Jul 23, 2026
CVE-2026-15017: Improper Privilege Management8.8 HighN/A0%Jul 23, 2026
CVE-2026-15015: Missing Authorization9.8 CriticalN/A1%Jul 23, 2026
CVE-2026-15011: Improper Control of Generation of Code9.8 CriticalN/A0%Jul 23, 2026
CVE-2026-14481: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 23, 2026
CVE-2026-14282: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Jul 23, 2026
CVE-2026-13119: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Jul 23, 2026
CVE-2026-13009: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Jul 23, 2026
CVE-2026-52688: Improper Certificate Validation7.5 HighN/A0%Jul 23, 2026
CVE-2026-52686: Improper Verification of Cryptographic Signature3.7 LowN/A0%Jul 23, 2026
CVE-2026-52684: Undefined Security Weakness3.7 LowN/A0%Jul 23, 2026
27326-27350 of 559420