The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-44304: Improper Neutralization of Special Elements used in an LDAP Query8.1 HighN/A0%May 12, 2026
CVE-2026-42844: Unrestricted Upload of File with Dangerous Type8.8 High8.7 High0%May 12, 2026
CVE-2026-42268: Integer Underflow (Wrap or Wraparound)7.5 High8.2 High0%May 12, 2026
CVE-2026-26289: Incorrect Authorization8.2 High8.4 High0%May 12, 2026
CVE-2026-44403: Improper Control of Generation of Code7.2 High8.6 High2%May 12, 2026
CVE-2026-44224: Improper Privilege Management8.8 High8.6 High1%May 12, 2026
CVE-2026-44873: Insufficient Session Expiration5.4 MediumN/A0%May 12, 2026
CVE-2026-44864: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%May 12, 2026
CVE-2026-44863: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%May 12, 2026
CVE-2026-44862: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%May 12, 2026
CVE-2026-44861: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%May 12, 2026
CVE-2026-44860: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A1%May 12, 2026
CVE-2026-44859: Stack-based Buffer Overflow7.2 HighN/A1%May 12, 2026
CVE-2026-44858: Stack-based Buffer Overflow7.2 HighN/A1%May 12, 2026
CVE-2026-44857: Stack-based Buffer Overflow7.2 HighN/A1%May 12, 2026
CVE-2026-44856: Stack-based Buffer Overflow7.2 HighN/A1%May 12, 2026
CVE-2026-44855: Stack-based Buffer Overflow7.2 HighN/A1%May 12, 2026
CVE-2026-34653: Improper Limitation of a Pathname to a Restricted Directory8.7 HighN/A1%May 12, 2026
CVE-2026-8431: Improper Neutralization of Special Elements used in a Command7.2 High9.4 Critical1%May 12, 2026
CVE-2026-44183: Authentication Bypass by Spoofing9.8 CriticalN/A0%May 12, 2026
CVE-2026-42303: Authentication Bypass Using an Alternate Path or ChannelN/A6.1 Medium1%May 12, 2026
CVE-2025-70842: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%May 12, 2026
CVE-2026-7428: Use of Default CredentialsN/A9.2 Critical0%May 12, 2026
CVE-2026-6813: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%May 12, 2026
CVE-2026-6800: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%May 12, 2026
3351-3375 of 17506