The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-61392: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Jul 22, 2026
CVE-2026-61391: Stack-based Buffer Overflow7.2 HighN/A1%Jul 22, 2026
CVE-2026-61390: Heap-based Buffer Overflow7.7 HighN/A0%Jul 22, 2026
CVE-2026-57600: Improper Input Validation7.5 HighN/A0%Jul 22, 2026
CVE-2026-57599: Improper Privilege Management6.6 MediumN/A0%Jul 22, 2026
CVE-2026-4773: Improper Validation of Specified Type of Input8.1 HighN/A0%Jul 22, 2026
CVE-2026-44192: Improper Limitation of a Pathname to a Restricted Directory6.6 MediumN/A0%Jul 22, 2026
CVE-2026-44190: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A1%Jul 22, 2026
CVE-2026-44189: Improper Neutralization of Argument Delimiters in a Command7.8 HighN/A1%Jul 22, 2026
CVE-2026-44187: Plaintext Storage of a Password3.3 LowN/A0%Jul 22, 2026
CVE-2026-16551: Loop with Unreachable Exit ConditionN/A6.9 Medium0%Jul 22, 2026
CVE-2026-16544: Missing Authorization6.5 MediumN/A0%Jul 22, 2026
CVE-2025-13146: Improper Control of Generation of Code6.5 MediumN/A0%Jul 22, 2026
CVE-2026-16473: Out-of-bounds Read4.3 MediumN/A0%Jul 22, 2026
CVE-2026-14551: Creation of Temporary File in Directory with Insecure Permissions8.8 HighN/A0%Jul 22, 2026
CVE-2026-63264: Improper Neutralization of Input During Web Page GenerationN/A5.3 Medium0%Jul 22, 2026
CVE-2026-2406: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Jul 22, 2026
CVE-2026-15787: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jul 22, 2026
CVE-2026-63048: Unrestricted Upload of File with Dangerous TypeN/A9.4 Critical0%Jul 22, 2026
CVE-2026-63047: Improper Access Control7.5 HighN/A0%Jul 22, 2026
CVE-2026-45820: Loop with Unreachable Exit Condition7.5 High6.6 Medium0%Jul 22, 2026
CVE-2026-3821: Improper Neutralization of Special Elements used in an OS Command8.8 HighN/A1%Jul 22, 2026
CVE-2026-14322: Improper Access Control5.3 MediumN/A0%Jul 22, 2026
CVE-2026-12987: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Jul 22, 2026
CVE-2026-12968: Improper Neutralization of Input During Web Page Generation8.8 HighN/A0%Jul 22, 2026
28076-28100 of 566702