The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-7484: External Control of Assumed-Immutable Web Parameter5.3 MediumN/A0%Jul 24, 2026
CVE-2026-66144: Uncontrolled Resource Consumption7.5 HighN/A0%Jul 24, 2026
CVE-2026-66143: Uncontrolled Resource Consumption7.5 HighN/A0%Jul 24, 2026
CVE-2026-66142: Uncontrolled Resource Consumption7.5 HighN/A0%Jul 24, 2026
CVE-2026-66009: Generation of Error Message Containing Sensitive InformationN/A6.3 Medium0%Jul 24, 2026
CVE-2026-66008: Generation of Error Message Containing Sensitive InformationN/A6.3 Medium0%Jul 24, 2026
CVE-2026-46452: Improper Input Validation5.3 MediumN/A0%Jul 24, 2026
CVE-2026-45816: NULL Pointer Dereference7.5 HighN/A0%Jul 24, 2026
CVE-2026-45815: Reachable Assertion7.5 HighN/A0%Jul 24, 2026
CVE-2026-45813: Out-of-bounds Write8.8 HighN/A0%Jul 24, 2026
CVE-2026-45812: Incorrect Calculation of Buffer Size6.5 MediumN/A0%Jul 24, 2026
CVE-2026-45811: Buffer Copy without Checking Size of Input7.5 HighN/A0%Jul 24, 2026
CVE-2026-16743: Improper Privilege Management5.5 MediumN/A0%Jul 24, 2026
CVE-2026-16730: Improper Handling of Exceptional Conditions5.5 MediumN/A0%Jul 24, 2026
CVE-2026-15810: Improper Neutralization of Input During Web Page GenerationN/A8.7 High0%Jul 24, 2026
CVE-2026-15243: Improper Validation of Certificate with Host MismatchN/A7.4 High0%Jul 24, 2026
CVE-2026-10610: Improper Privilege ManagementN/A8.5 High0%Jul 24, 2026
CVE-2026-66010: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Jul 24, 2026
CVE-2026-7483: Improper Privilege ManagementN/A8.5 High0%Jul 24, 2026
CVE-2026-16634: Use of Unmaintained Third Party Components9.8 CriticalN/A0%Jul 24, 2026
CVE-2026-15663: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Jul 24, 2026
CVE-2026-15401: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Jul 24, 2026
CVE-2026-10033: Missing Authorization7.3 HighN/A0%Jul 24, 2026
CVE-2026-63317: Use of Externally-Controlled Input to Select Classes or Code5.6 MediumN/A0%Jul 24, 2026
CVE-2026-56392: Heap-based Buffer OverflowN/A1.8 Low0%Jul 24, 2026
28376-28400 of 400317