The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-66006: Missing Authentication for Critical Function5.3 Medium6.9 Medium0%Jul 24, 2026
CVE-2026-66005: Permissive List of Allowed Inputs6.3 Medium5.3 Medium0%Jul 24, 2026
CVE-2026-66004: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium6.0 Medium0%Jul 24, 2026
CVE-2026-58586: Dependency on Vulnerable Third-Party Component9.8 CriticalN/A0%Jul 24, 2026
CVE-2026-55732: Out-of-bounds ReadN/A8.7 High0%Jul 24, 2026
CVE-2026-55731: Unchecked Input for Loop ConditionN/A6.6 Medium0%Jul 24, 2026
CVE-2026-55730: Improper Neutralization of Input During Web Page GenerationN/A8.7 High0%Jul 24, 2026
CVE-2026-55729: Exposure of Sensitive Information to an Unauthorized ActorN/A7.7 High0%Jul 24, 2026
CVE-2026-55728: Stack-based Buffer OverflowN/A3.8 Low0%Jul 24, 2026
CVE-2026-49326: Missing Authorization6.5 MediumN/A0%Jul 24, 2026
CVE-2026-17059: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Jul 24, 2026
CVE-2026-16802: Cleartext Storage of Sensitive Information6.5 MediumN/A0%Jul 24, 2026
CVE-2026-16801: Improper Control of Generation of Code8.8 HighN/A0%Jul 24, 2026
CVE-2026-16800: Improper Control of Generation of Code8.8 HighN/A0%Jul 24, 2026
CVE-2026-16799: Missing Authorization5.0 MediumN/A0%Jul 24, 2026
CVE-2026-16798: Insertion of Sensitive Information Into Sent Data6.5 MediumN/A0%Jul 24, 2026
CVE-2026-12504: Improper AuthenticationN/A8.4 High0%Jul 24, 2026
CVE-2026-12503: Improper Link Resolution Before File AccessN/A9.2 Critical0%Jul 24, 2026
CVE-2026-12502: Improper Privilege ManagementN/A8.4 High0%Jul 24, 2026
CVE-2026-12496: Improper Neutralization of Input During Web Page GenerationN/A8.7 High0%Jul 24, 2026
CVE-2026-56163: Missing Authentication for Critical Function10.0 CriticalN/A1%Jul 24, 2026
CVE-2026-58630: Improper Access Control10.0 CriticalN/A1%Jul 24, 2026
CVE-2026-57106: Server-Side Request Forgery (SSRF)10.0 CriticalN/A1%Jul 24, 2026
CVE-2026-17048: Exposure of Sensitive Information to an Unauthorized Actor4.9 MediumN/A0%Jul 24, 2026
CVE-2026-9765: Improper Access Control7.1 HighN/A0%Jul 24, 2026
28351-28375 of 400317