The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-15802: Relative Path Traversal8.1 HighN/A1%Jul 22, 2026
CVE-2026-56844: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.4 High0%Jul 22, 2026
CVE-2026-16492: Improper Neutralization of Special Elements used in an OS Command5.5 Medium2.0 Low2%Jul 22, 2026
CVE-2026-16490: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Jul 22, 2026
CVE-2026-63263: Uncontrolled Resource Consumption6.5 MediumN/A0%Jul 22, 2026
CVE-2026-63262: Missing Authorization4.3 MediumN/A0%Jul 22, 2026
CVE-2026-16489: Improper Neutralization of Special Elements used in an OS Command5.3 Medium1.9 Low1%Jul 22, 2026
CVE-2026-16488: Improper Neutralization of Special Elements used in an OS Command5.0 Medium1.3 Low1%Jul 22, 2026
CVE-2026-63261: Uncontrolled Resource Consumption6.5 MediumN/A0%Jul 21, 2026
CVE-2026-63260: Uncontrolled Resource Consumption6.5 MediumN/A0%Jul 21, 2026
CVE-2026-63259: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Jul 21, 2026
CVE-2026-63145: Incorrect Authorization4.3 MediumN/A0%Jul 21, 2026
CVE-2026-63144: Uncontrolled Recursion6.5 MediumN/A0%Jul 21, 2026
CVE-2026-63143: Missing Authorization4.3 MediumN/A0%Jul 21, 2026
CVE-2026-63142: Incorrect Authorization5.0 MediumN/A0%Jul 21, 2026
CVE-2026-56820: Improper Certificate Validation9.1 CriticalN/A0%Jul 21, 2026
CVE-2026-56819: Uncontrolled Resource Consumption7.5 HighN/A1%Jul 21, 2026
CVE-2026-56817: Improper Restriction of XML External Entity Reference9.8 Critical8.3 High1%Jul 21, 2026
CVE-2026-16517: Integer Overflow or Wraparound2.9 LowN/A0%Jul 21, 2026
CVE-2026-16486: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Jul 21, 2026
CVE-2026-16485: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Jul 21, 2026
CVE-2026-16424: Use After Free9.6 CriticalN/A0%Jul 21, 2026
CVE-2026-16423: Use After Free8.8 HighN/A0%Jul 21, 2026
CVE-2026-16422: Improper Input Validation7.5 HighN/A0%Jul 21, 2026
CVE-2026-16421: Improper Input Validation8.8 HighN/A0%Jul 21, 2026
28101-28125 of 566702