The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-16723: Improper Input Validation9.0 CriticalN/A16%Jul 23, 2026
CVE-2026-16287: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A1%Jul 23, 2026
CVE-2024-58330: Improper Access Control7.5 HighN/A1%Jul 23, 2026
CVE-2024-58023: Cleartext Storage of Sensitive Information8.4 HighN/A0%Jul 23, 2026
CVE-2026-9729: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 23, 2026
CVE-2026-9713: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Jul 23, 2026
CVE-2026-9635: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 23, 2026
CVE-2026-59678: Incorrect AuthorizationN/A7.1 High0%Jul 23, 2026
CVE-2026-59677: Missing AuthorizationN/A6.8 Medium0%Jul 23, 2026
CVE-2026-12421: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Jul 23, 2026
CVE-2026-9577: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Jul 23, 2026
CVE-2026-9066: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Jul 23, 2026
CVE-2026-59676: Time-of-check Time-of-use (TOCTOU) Race ConditionN/A5.8 Medium0%Jul 23, 2026
CVE-2026-14291: Improper Authentication7.5 HighN/A1%Jul 23, 2026
CVE-2026-12082: Missing Authorization7.5 HighN/A0%Jul 23, 2026
CVE-2026-7534: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Jul 23, 2026
CVE-2026-7232: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Jul 23, 2026
CVE-2026-64600: Concurrent Execution using Shared Resource with Improper Synchronization7.8 HighN/A0%Jul 23, 2026
CVE-2026-63226: Improper Restriction of Communication Channel to Intended Endpoints5.8 Medium6.9 Medium0%Jul 23, 2026
CVE-2026-6390: Use of Externally-Controlled Format String6.8 MediumN/A0%Jul 23, 2026
CVE-2026-7120: Incorrect Behavior Order: Validate Before Canonicalize5.3 MediumN/A0%Jul 23, 2026
CVE-2026-15074: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Jul 23, 2026
CVE-2026-16653: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium5.5 Medium1%Jul 23, 2026
CVE-2026-21723: Uncontrolled Resource Consumption5.3 MediumN/A0%Jul 23, 2026
CVE-2026-16632: Improper Input Validation7.3 High5.5 Medium1%Jul 23, 2026
27351-27375 of 559420