The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-8494: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Jun 17, 2026
CVE-2026-8089: Undefined Security Weakness7.1 HighN/A0%Jun 17, 2026
CVE-2026-53876: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High2%Jun 17, 2026
CVE-2026-12165: Improper Privilege Management8.8 HighN/A0%Jun 17, 2026
CVE-2026-12115: Deserialization of Untrusted Data6.6 MediumN/A1%Jun 17, 2026
CVE-2026-11975: Improper Neutralization of Input During Web Page GenerationN/A6.2 Medium0%Jun 17, 2026
CVE-2026-11410: Improper Neutralization of Special Elements used in an OS Command7.2 High8.5 High3%Jun 17, 2026
CVE-2026-11409: Improper Neutralization of Special Elements used in an OS Command7.2 High8.5 High3%Jun 17, 2026
CVE-2025-15641: Exposed IOCTL with Insufficient Access ControlN/A6.8 Medium0%Jun 17, 2026
CVE-2026-46978: Undefined Security Weakness10.0 CriticalN/A0%Jun 17, 2026
CVE-2026-46966: Undefined Security Weakness7.5 HighN/A0%Jun 17, 2026
CVE-2026-46965: Undefined Security Weakness8.8 HighN/A0%Jun 17, 2026
CVE-2026-46964: Undefined Security Weakness9.9 CriticalN/A0%Jun 17, 2026
CVE-2026-46963: Undefined Security Weakness9.9 CriticalN/A0%Jun 17, 2026
CVE-2026-22313: Improper Neutralization of Special Elements used in an OS Command9.1 CriticalN/A1%Jun 16, 2026
CVE-2026-53776: Insufficient Session Expiration9.1 Critical9.3 Critical1%Jun 16, 2026
CVE-2025-14272: Missing AuthorizationN/A8.3 High0%Jun 16, 2026
CVE-2026-12225: Authentication Bypass Using an Alternate Path or ChannelN/A8.7 High0%Jun 16, 2026
CVE-2026-8176: Improper Privilege Management7.5 HighN/A1%Jun 16, 2026
CVE-2026-10780: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Jun 16, 2026
CVE-2025-60175: Server-Side Request Forgery (SSRF)4.4 MediumN/A0%Jun 15, 2026
CVE-2026-50884: Improper Access Control8.8 HighN/A0%Jun 15, 2026
CVE-2026-50881: Improper Access Control8.1 HighN/A0%Jun 15, 2026
CVE-2026-38812: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Jun 15, 2026
CVE-2026-49954: Improper Control of Filename for Include/Require Statement in PHP Program7.2 High8.6 High1%Jun 15, 2026
2826-2850 of 17495