The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-54106: Improper Verification of Source of a Communication Channel4.7 Medium5.1 Medium0%Jun 18, 2026
CVE-2026-11791: Use After Free5.0 MediumN/A0%Jun 18, 2026
CVE-2025-52465: External Control of File Name or Path7.2 HighN/A1%Jun 18, 2026
CVE-2025-27511: Deserialization of Untrusted Data7.2 HighN/A1%Jun 18, 2026
CVE-2026-11958: Uncontrolled Search Path ElementN/A7.3 High0%Jun 18, 2026
CVE-2026-55742: Cross-Site Request Forgery (CSRF)9.6 Critical9.4 Critical0%Jun 18, 2026
CVE-2026-55741: Cross-Site Request Forgery (CSRF)8.8 High8.7 High0%Jun 18, 2026
CVE-2026-12102: Authorization Bypass Through User-Controlled Key2.7 LowN/A0%Jun 18, 2026
CVE-2026-9199: Missing Authorization4.3 MediumN/A0%Jun 18, 2026
CVE-2026-11784: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Jun 18, 2026
CVE-2026-11777: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Jun 18, 2026
CVE-2026-11776: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Jun 18, 2026
CVE-2026-11358: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%Jun 18, 2026
CVE-2026-11357: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Jun 18, 2026
CVE-2026-10736: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Jun 18, 2026
CVE-2026-12407: Missing Authorization8.8 HighN/A0%Jun 18, 2026
CVE-2026-54445: Observable Response DiscrepancyN/A6.9 Medium0%Jun 17, 2026
CVE-2026-53676: Improperly Controlled Modification of Object Prototype Attributes7.2 High8.6 High1%Jun 17, 2026
CVE-2026-48821: Improper Neutralization of Input During Web Page Generation5.8 MediumN/A0%Jun 17, 2026
CVE-2026-48823: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Jun 17, 2026
CVE-2026-11407: Improper Neutralization of Special Elements Used in a Template Engine7.2 High8.6 High1%Jun 17, 2026
CVE-2026-10741: Incorrect Authorization4.9 Medium5.9 Medium0%Jun 17, 2026
CVE-2026-55196: Missing Authentication for Critical Function9.1 Critical9.1 Critical1%Jun 17, 2026
CVE-2026-20181: Improper Limitation of a Pathname to a Restricted Directory9.1 CriticalN/A9%Jun 17, 2026
CVE-2026-9591: Cross-Site Request Forgery (CSRF)N/A6.9 Medium0%Jun 17, 2026
2801-2825 of 17495