The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-42832: Improper Access Control7.7 HighN/A0%May 12, 2026
CVE-2026-40420: Improper Access Control8.8 HighN/A0%May 12, 2026
CVE-2026-35436: Insufficient Granularity of Access Control8.8 HighN/A0%May 12, 2026
CVE-2026-40418: Use After Free7.8 HighN/A0%May 12, 2026
CVE-2026-40367: Untrusted Pointer Dereference8.4 HighN/A0%May 12, 2026
CVE-2026-40365: Insufficient Granularity of Access Control8.8 HighN/A0%May 12, 2026
CVE-2026-40362: Heap-based Buffer Overflow7.8 HighN/A0%May 12, 2026
CVE-2026-40361: Use After Free8.4 HighN/A0%May 12, 2026
CVE-2026-40359: Use After Free7.8 HighN/A0%May 12, 2026
CVE-2026-40358: Use After Free8.4 HighN/A0%May 12, 2026
CVE-2026-40357: Deserialization of Untrusted Data8.8 HighN/A1%May 12, 2026
CVE-2026-33112: Deserialization of Untrusted Data8.8 HighN/A1%May 12, 2026
CVE-2026-33110: Deserialization of Untrusted Data8.8 HighN/A1%May 12, 2026
CVE-2026-42831: Heap-based Buffer Overflow7.8 HighN/A0%May 12, 2026
CVE-2026-41102: Improper Access Control7.1 HighN/A0%May 12, 2026
CVE-2026-41101: Improper Access Control7.1 HighN/A0%May 12, 2026
CVE-2026-40421: External Control of File Name or Path4.3 MediumN/A0%May 12, 2026
CVE-2026-40419: Use After Free7.8 HighN/A0%May 12, 2026
CVE-2026-40368: Deserialization of Untrusted Data8.0 HighN/A0%May 12, 2026
CVE-2026-40366: Use After Free8.4 HighN/A0%May 12, 2026
CVE-2026-40364: Access of Resource Using Incompatible Type8.4 HighN/A0%May 12, 2026
CVE-2026-40363: Heap-based Buffer Overflow8.4 HighN/A0%May 12, 2026
CVE-2026-40360: Out-of-bounds Read7.8 HighN/A0%May 12, 2026
CVE-2026-35440: Files or Directories Accessible to External Parties5.5 MediumN/A0%May 12, 2026
CVE-2026-35439: Deserialization of Untrusted Data8.8 HighN/A1%May 12, 2026
401-425 of 1558