The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-35425: Improper Access Control8.0 HighN/A0%Jul 24, 2026
CVE-2026-56160: Improper Authorization9.1 CriticalN/A1%Jul 23, 2026
CVE-2026-54120: Improper Input Validation9.9 CriticalN/A1%Jul 23, 2026
CVE-2026-56165: Heap-based Buffer Overflow9.8 CriticalN/A1%Jul 23, 2026
CVE-2026-56167: Server-Side Request Forgery (SSRF)8.5 HighN/A0%Jul 23, 2026
CVE-2026-50044: Inadequate Encryption Strength6.8 Medium7.6 High0%Jul 23, 2026
CVE-2026-44955: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 Medium6.9 Medium0%Jul 23, 2026
CVE-2026-42933: Unintended Proxy or Intermediary10.0 Critical10.0 Critical0%Jul 23, 2026
CVE-2026-40430: Plaintext Storage of a Password7.5 High8.7 High0%Jul 23, 2026
CVE-2026-28698: Exposure of Sensitive System Information to an Unauthorized Control Sphere8.6 High9.2 Critical0%Jul 23, 2026
CVE-2026-16767: Improper Limitation of a Pathname to a Restricted Directory6.5 Medium5.5 Medium0%Jul 23, 2026
CVE-2026-65694: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High1%Jul 23, 2026
CVE-2026-65604: Improper Input Validation8.2 High8.8 High0%Jul 23, 2026
CVE-2026-63732: Improper Neutralization of Special Elements used in an OS Command9.9 Critical9.4 Critical1%Jul 23, 2026
CVE-2026-63313: Server-Side Request Forgery (SSRF)7.7 High8.3 High0%Jul 23, 2026
CVE-2026-16807: Out-of-bounds Write8.8 HighN/A0%Jul 23, 2026
CVE-2026-16806: Use After Free8.8 HighN/A0%Jul 23, 2026
CVE-2026-16805: Use After Free8.8 HighN/A0%Jul 23, 2026
CVE-2026-16804: Use After Free8.3 HighN/A0%Jul 23, 2026
CVE-2026-16765: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Jul 23, 2026
CVE-2026-16764: Improper Privilege Management6.3 Medium2.1 Low0%Jul 23, 2026
CVE-2026-16763: Improper Neutralization of Special Elements used in an OS Command5.3 Medium1.9 Low1%Jul 23, 2026
CVE-2025-71389: Improper Control of Generation of Code10.0 Critical10.0 Critical1%Jul 23, 2026
CVE-2024-58355: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)8.9 High9.3 Critical0%Jul 23, 2026
CVE-2024-58354: Improper Neutralization of Special Elements used in a Command9.9 Critical8.5 High0%Jul 23, 2026
28451-28475 of 406335