The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-35019: Use of Hard-coded Cryptographic Key8.1 High9.2 Critical1%Jun 23, 2026
CVE-2026-28496: Improper Neutralization of Special Elements Used in a Template EngineN/A9.4 Critical2%Jun 23, 2026
CVE-2026-56222: Authorization Bypass Through User-Controlled Key7.2 High8.6 High1%Jun 23, 2026
CVE-2026-8378: Undefined Security Weakness5.4 MediumN/A0%Jun 23, 2026
CVE-2026-10658: Out-of-bounds Write7.1 HighN/A0%Jun 23, 2026
CVE-2026-10651: Improper Input Validation6.5 MediumN/A0%Jun 23, 2026
CVE-2026-11834: Improper Neutralization of Special Elements used in an OS CommandN/A8.7 High0%Jun 22, 2026
CVE-2026-54269: Uncontrolled Recursion5.3 MediumN/A0%Jun 22, 2026
CVE-2026-8823: Incorrect Authorization3.8 LowN/A0%Jun 22, 2026
CVE-2026-7165: Improper Input ValidationN/A9.4 Critical0%Jun 22, 2026
CVE-2026-5139: Missing Authorization5.4 MediumN/A0%Jun 22, 2026
CVE-2026-56450: Improper Restriction of Excessive Authentication AttemptsN/A5.1 Medium1%Jun 22, 2026
CVE-2026-56447: Inclusion of Functionality from Untrusted Control Sphere7.2 High9.3 Critical1%Jun 22, 2026
CVE-2026-56446: Improper Control of Generation of Code7.2 High8.7 High0%Jun 22, 2026
CVE-2026-54099: Improper Privilege Management8.8 HighN/A0%Jun 22, 2026
CVE-2026-12602: Incorrect Default PermissionsN/A8.8 High0%Jun 22, 2026
CVE-2026-10601: Improper Limitation of a Pathname to a Restricted Directory5.4 MediumN/A0%Jun 22, 2026
CVE-2026-42129: Improper Limitation of a Pathname to a Restricted Directory7.7 HighN/A0%Jun 22, 2026
CVE-2026-12862: Improper Neutralization of Input LeadersN/A5.1 Medium0%Jun 22, 2026
CVE-2025-4994: Authentication Bypass by Primary WeaknessN/A8.7 High0%Jun 22, 2026
CVE-2026-8157: Undefined Security Weakness8.8 HighN/A0%Jun 22, 2026
CVE-2026-6858: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Jun 22, 2026
CVE-2026-8918: Permissive List of Allowed InputsN/A7.1 High0%Jun 22, 2026
CVE-2026-56396: Missing Authorization8.8 High8.7 High0%Jun 21, 2026
CVE-2026-56393: Improper Neutralization of Input During Web Page Generation4.8 Medium4.6 Medium0%Jun 21, 2026
2751-2775 of 17493