The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-12082: Missing Authorization7.5 HighN/A0%Jul 23, 2026
CVE-2026-7534: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Jul 23, 2026
CVE-2026-7232: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Jul 23, 2026
CVE-2026-64600: Concurrent Execution using Shared Resource with Improper Synchronization7.8 HighN/A0%Jul 23, 2026
CVE-2026-63226: Improper Restriction of Communication Channel to Intended Endpoints5.8 Medium6.9 Medium0%Jul 23, 2026
CVE-2026-6390: Use of Externally-Controlled Format String6.8 MediumN/A0%Jul 23, 2026
CVE-2026-7120: Incorrect Behavior Order: Validate Before Canonicalize5.3 MediumN/A0%Jul 23, 2026
CVE-2026-15074: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Jul 23, 2026
CVE-2026-16653: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium5.5 Medium1%Jul 23, 2026
CVE-2026-21723: Uncontrolled Resource Consumption5.3 MediumN/A0%Jul 23, 2026
CVE-2026-16632: Improper Input Validation7.3 High5.5 Medium1%Jul 23, 2026
CVE-2026-16631: Improper Neutralization of Special Elements used in an OS Command5.3 Medium1.9 Low1%Jul 23, 2026
CVE-2026-61246: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60455: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60439: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60373: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60372: Improper Privilege Management9.8 CriticalN/A1%Jul 22, 2026
CVE-2026-60371: Exposure of Sensitive Information to an Unauthorized Actor8.0 HighN/A0%Jul 22, 2026
CVE-2026-60370: Improper Restriction of Rendered UI Layers or Frames7.5 HighN/A0%Jul 22, 2026
CVE-2026-60369: Improper Privilege Management9.9 CriticalN/A0%Jul 22, 2026
CVE-2026-60368: Use of Unmaintained Third Party Components8.8 HighN/A1%Jul 22, 2026
CVE-2026-60367: Improper Privilege Management9.8 CriticalN/A1%Jul 22, 2026
CVE-2026-60366: Improper Privilege Management10.0 CriticalN/A1%Jul 22, 2026
CVE-2026-38766: Improper Privilege Management7.8 HighN/A0%Jul 22, 2026
CVE-2026-38765: Improper Privilege Management7.8 HighN/A0%Jul 22, 2026
27376-27400 of 397021