The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-55973: Improper Input Validation7.5 HighN/A0%Jul 22, 2026
CVE-2026-55717: NULL Pointer Dereference5.9 MediumN/A0%Jul 22, 2026
CVE-2026-55708: Initialization of a Resource with an Insecure Default3.1 LowN/A0%Jul 22, 2026
CVE-2026-54478: Authentication Bypass by Spoofing3.7 LowN/A0%Jul 22, 2026
CVE-2026-53910: Integer Overflow or WraparoundN/A2.1 Low0%Jul 22, 2026
CVE-2026-52863: Use After Free5.9 MediumN/A0%Jul 22, 2026
CVE-2026-50252: Acceptance of Extraneous Untrusted Data With Trusted Data9.3 Critical5.7 Medium0%Jul 22, 2026
CVE-2026-50251: Incomplete List of Disallowed Inputs5.3 MediumN/A0%Jul 22, 2026
CVE-2026-50248: Insufficient Verification of Data Authenticity6.5 MediumN/A0%Jul 22, 2026
CVE-2026-50243: Use of Less Trusted Source3.7 Low6.3 Medium0%Jul 22, 2026
CVE-2026-50046: Use After Free5.9 MediumN/A0%Jul 22, 2026
CVE-2026-50045: Insufficient Control of Network Message Volume (Network Amplification)5.3 MediumN/A0%Jul 22, 2026
CVE-2026-46582: Improperly Implemented Security Check for Standard3.7 LowN/A0%Jul 22, 2026
CVE-2026-44690: Insufficient Verification of Data Authenticity7.5 HighN/A0%Jul 22, 2026
CVE-2026-44687: Off-by-one Error3.7 LowN/A0%Jul 22, 2026
CVE-2026-44621: Improper Check for Unusual or Exceptional Conditions5.9 MediumN/A0%Jul 22, 2026
CVE-2026-42955: Operation on a Resource after Expiration or Release3.7 LowN/A0%Jul 22, 2026
CVE-2026-41637: Missing Release of Resource after Effective Lifetime3.7 LowN/A0%Jul 22, 2026
CVE-2026-40691: Heap-based Buffer Overflow7.5 HighN/A0%Jul 22, 2026
CVE-2026-16560: Insufficient Granularity of Access Control5.3 MediumN/A0%Jul 22, 2026
CVE-2026-16232: Improper Authentication9.8 Critical9.3 Critical72%Jul 22, 2026
CVE-2026-14932: Use of Hard-coded Cryptographic Key6.5 MediumN/A0%Jul 22, 2026
CVE-2026-14865: Improper Restriction of Recursive Entity References in DTDs5.3 MediumN/A0%Jul 22, 2026
CVE-2026-14586: Reachable Assertion5.9 MediumN/A0%Jul 22, 2026
CVE-2026-13192: Server-Side Request Forgery (SSRF)6.5 MediumN/A0%Jul 22, 2026
27576-27600 of 552652