The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-21530: Double Free6.7 MediumN/A0%May 12, 2026
CVE-2026-33822: Out-of-bounds Read6.1 MediumN/A0%Apr 14, 2026
CVE-2026-33115: Use After Free8.4 HighN/A0%Apr 14, 2026
CVE-2026-33114: Untrusted Pointer Dereference8.4 HighN/A0%Apr 14, 2026
CVE-2026-33095: Use After Free7.8 HighN/A0%Apr 14, 2026
CVE-2026-32201: Improper Input Validation6.5 MediumN/A1%Apr 14, 2026
CVE-2026-32200: Use After Free7.8 HighN/A0%Apr 14, 2026
CVE-2026-32199: Use After Free7.8 HighN/A0%Apr 14, 2026
CVE-2026-32198: Use After Free7.8 HighN/A0%Apr 14, 2026
CVE-2026-32197: Use After Free7.8 HighN/A0%Apr 14, 2026
CVE-2026-32190: Use After Free8.4 HighN/A0%Apr 14, 2026
CVE-2026-23657: Use After Free7.8 HighN/A0%Apr 14, 2026
CVE-2026-32189: Use After Free7.8 HighN/A0%Apr 14, 2026
CVE-2026-32188: Out-of-bounds Read7.1 HighN/A0%Apr 14, 2026
CVE-2026-20945: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Apr 14, 2026
CVE-2026-26144: Improper Neutralization of Input During Web Page Generation7.5 HighN/A0%Mar 10, 2026
CVE-2026-26110: Access of Resource Using Incompatible Type8.4 HighN/A0%Mar 10, 2026
CVE-2026-26109: Out-of-bounds Read8.4 HighN/A0%Mar 10, 2026
CVE-2026-26108: Heap-based Buffer Overflow7.8 HighN/A0%Mar 10, 2026
CVE-2026-26107: Use After Free7.8 HighN/A0%Mar 10, 2026
CVE-2026-26106: Improper Input Validation8.8 HighN/A0%Mar 10, 2026
CVE-2026-26134: Integer Overflow or Wraparound7.8 HighN/A0%Mar 10, 2026
CVE-2026-26114: Deserialization of Untrusted Data8.8 HighN/A1%Mar 10, 2026
CVE-2026-26113: Untrusted Pointer Dereference8.4 HighN/A0%Mar 10, 2026
CVE-2026-26112: Untrusted Pointer Dereference7.8 HighN/A0%Mar 10, 2026
426-450 of 1558