The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-26105: Improper Neutralization of Input During Web Page Generation8.1 HighN/A0%Mar 10, 2026
CVE-2026-25180: Out-of-bounds Read5.5 MediumN/A0%Mar 10, 2026
CVE-2026-24285: Use After Free7.0 HighN/A0%Mar 10, 2026
CVE-2026-20846: Buffer Over-read7.5 HighN/A0%Feb 10, 2026
CVE-2026-21261: Out-of-bounds Read5.5 MediumN/A0%Feb 10, 2026
CVE-2026-21511: Deserialization of Untrusted Data7.5 HighN/A0%Feb 10, 2026
CVE-2026-21514: Reliance on Untrusted Inputs in a Security Decision7.8 HighN/A4%Feb 10, 2026
CVE-2026-21260: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Feb 10, 2026
CVE-2026-21258: Improper Input Validation5.5 MediumN/A0%Feb 10, 2026
CVE-2026-21259: Heap-based Buffer Overflow7.8 HighN/A0%Feb 10, 2026
CVE-2026-21509: Reliance on Untrusted Inputs in a Security Decision7.8 HighN/A7%Jan 26, 2026
CVE-2026-20958: Server-Side Request Forgery (SSRF)5.4 MediumN/A0%Jan 13, 2026
CVE-2026-20957: Integer Underflow (Wrap or Wraparound)7.8 HighN/A0%Jan 13, 2026
CVE-2026-20952: Use After Free8.4 HighN/A0%Jan 13, 2026
CVE-2026-20950: Use After Free7.8 HighN/A0%Jan 13, 2026
CVE-2026-20949: Improper Access Control7.8 HighN/A0%Jan 13, 2026
CVE-2026-20948: Untrusted Pointer Dereference7.8 HighN/A0%Jan 13, 2026
CVE-2026-20947: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Jan 13, 2026
CVE-2026-20963: Deserialization of Untrusted Data9.8 CriticalN/A6%Jan 13, 2026
CVE-2026-20959: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Jan 13, 2026
CVE-2026-20956: Untrusted Pointer Dereference7.8 HighN/A0%Jan 13, 2026
CVE-2026-20955: Untrusted Pointer Dereference7.8 HighN/A0%Jan 13, 2026
CVE-2026-20953: Use After Free8.4 HighN/A0%Jan 13, 2026
CVE-2026-20951: Improper Input Validation7.8 HighN/A0%Jan 13, 2026
CVE-2026-20946: Out-of-bounds Read7.8 HighN/A0%Jan 13, 2026
451-475 of 1558