The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-48029: Out-of-bounds Read7.1 HighN/A0%Jul 22, 2026
CVE-2026-2395: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Jul 22, 2026
CVE-2026-14985: Improper Limitation of a Pathname to a Restricted Directory7.8 HighN/A0%Jul 22, 2026
CVE-2026-13321: Origin Validation Error8.6 HighN/A0%Jul 22, 2026
CVE-2026-13204: Reachable Assertion7.5 HighN/A1%Jul 22, 2026
CVE-2026-12617: Reachable Assertion7.5 HighN/A1%Jul 22, 2026
CVE-2026-11721: Improper Validation of Specified Quantity in Input7.5 HighN/A0%Jul 22, 2026
CVE-2026-11622: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Jul 22, 2026
CVE-2026-11605: Incorrect Behavior Order: Early Amplification7.5 HighN/A1%Jul 22, 2026
CVE-2026-11331: Improper Filtering of Special Elements7.5 HighN/A0%Jul 22, 2026
CVE-2026-10822: Reachable Assertion6.5 MediumN/A0%Jul 22, 2026
CVE-2026-10723: Improper Verification of Cryptographic Signature6.8 MediumN/A0%Jul 22, 2026
CVE-2026-62145: Improper Privilege Management7.5 HighN/A8%Jul 22, 2026
CVE-2026-62144: Improper Authentication9.1 CriticalN/A21%Jul 22, 2026
CVE-2026-56444: Missing Release of Resource after Effective Lifetime5.9 MediumN/A0%Jul 22, 2026
CVE-2026-56416: Improper Validation of Integrity Check Value4.8 MediumN/A0%Jul 22, 2026
CVE-2026-55990: Use of Uninitialized Variable5.9 MediumN/A0%Jul 22, 2026
CVE-2026-55973: Improper Input Validation7.5 HighN/A0%Jul 22, 2026
CVE-2026-55717: NULL Pointer Dereference5.9 MediumN/A0%Jul 22, 2026
CVE-2026-55708: Initialization of a Resource with an Insecure Default3.1 LowN/A0%Jul 22, 2026
CVE-2026-54478: Authentication Bypass by Spoofing3.7 LowN/A0%Jul 22, 2026
CVE-2026-53910: Integer Overflow or WraparoundN/A2.1 Low0%Jul 22, 2026
CVE-2026-52863: Use After Free5.9 MediumN/A0%Jul 22, 2026
CVE-2026-50252: Acceptance of Extraneous Untrusted Data With Trusted Data9.3 Critical5.7 Medium0%Jul 22, 2026
CVE-2026-50251: Incomplete List of Disallowed Inputs5.3 MediumN/A0%Jul 22, 2026
27501-27525 of 552652