The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-65013: Authorization Bypass Through User-Controlled Key8.8 High8.7 High1%Jul 22, 2026
CVE-2026-65012: Missing Authentication for Critical Function5.3 Medium6.3 Medium0%Jul 22, 2026
CVE-2026-65011: Missing Authorization4.3 Medium5.3 Medium0%Jul 22, 2026
CVE-2026-64831: Stack-based Buffer Overflow8.8 High8.7 High1%Jul 22, 2026
CVE-2026-64830: Heap-based Buffer Overflow8.8 High8.7 High1%Jul 22, 2026
CVE-2026-16615: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)6.8 MediumN/A0%Jul 22, 2026
CVE-2026-64828: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Jul 22, 2026
CVE-2026-49499: Generation of Incorrect Security Tokens8.8 HighN/A0%Jul 22, 2026
CVE-2026-46738: Improper Input Validation7.2 HighN/A0%Jul 22, 2026
CVE-2026-46737: Improper Input Validation7.2 HighN/A1%Jul 22, 2026
CVE-2026-44276: Exposure of Sensitive Information to an Unauthorized Actor4.4 MediumN/A0%Jul 22, 2026
CVE-2026-40714: Improper Input Validation7.2 HighN/A0%Jul 22, 2026
CVE-2026-40712: Improper Input Validation7.2 HighN/A0%Jul 22, 2026
CVE-2026-16607: Improper Privilege Management7.8 High8.5 High0%Jul 22, 2026
CVE-2026-16606: Improper Control of Generation of Code9.8 Critical9.3 Critical1%Jul 22, 2026
CVE-2026-16552: Undefined Security WeaknessN/AN/AN/AJul 22, 2026
CVE-2026-48029: Out-of-bounds Read7.1 HighN/A0%Jul 22, 2026
CVE-2026-2395: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Jul 22, 2026
CVE-2026-14985: Improper Limitation of a Pathname to a Restricted Directory7.8 HighN/A0%Jul 22, 2026
CVE-2026-13321: Origin Validation Error8.6 HighN/A0%Jul 22, 2026
CVE-2026-13204: Reachable Assertion7.5 HighN/A1%Jul 22, 2026
CVE-2026-12617: Reachable Assertion7.5 HighN/A1%Jul 22, 2026
CVE-2026-11721: Improper Validation of Specified Quantity in Input7.5 HighN/A0%Jul 22, 2026
CVE-2026-11622: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Jul 22, 2026
CVE-2026-11605: Incorrect Behavior Order: Early Amplification7.5 HighN/A1%Jul 22, 2026
27976-28000 of 566702