The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-61632: Improper Limitation of a Pathname to a Restricted Directory5.3 MediumN/A0%Aug 6, 2026
CVE-2026-42169: Incorrect Calculation of Buffer Size7.8 HighN/A0%Aug 4, 2026
CVE-2026-6694: Buffer Copy without Checking Size of Input5.5 MediumN/A0%Aug 3, 2026
CVE-2026-55497: Uncontrolled Resource Consumption6.5 MediumN/A1%Jul 31, 2026
CVE-2026-59941: Uncontrolled Resource Consumption7.5 High6.3 Medium1%Jul 28, 2026
CVE-2026-66040: Heap-based Buffer Overflow8.8 High8.7 High1%Jul 24, 2026
CVE-2026-47247: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Jul 21, 2026
CVE-2026-64612: Uncaught Exception7.5 HighN/A1%Jul 20, 2026
CVE-2026-52584: Stack-based Buffer Overflow7.1 HighN/A0%Jul 17, 2026
CVE-2026-47160: Server-Side Request Forgery (SSRF)5.8 MediumN/A0%Jul 15, 2026
CVE-2026-62294: Concurrent Execution using Shared Resource with Improper SynchronizationN/A5.1 Medium0%Jul 15, 2026
CVE-2026-61858: Improper Link Resolution Before File Access5.3 Medium4.8 Medium0%Jul 11, 2026
CVE-2026-15173: Heap-based Buffer Overflow5.5 MediumN/A0%Jul 8, 2026
CVE-2026-38968: Predictable from Observable State9.8 CriticalN/A1%Jul 2, 2026
CVE-2026-7311: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A1%Jul 2, 2026
CVE-2026-56365: Missing Release of Memory after Effective Lifetime5.3 Medium6.3 Medium0%Jun 30, 2026
CVE-2026-13587: Heap-based Buffer Overflow3.7 Low2.9 Low1%Jun 29, 2026
CVE-2026-54352: Improper Limitation of a Pathname to a Restricted Directory9.6 CriticalN/A0%Jun 26, 2026
CVE-2026-48945: Unrestricted Upload of File with Dangerous Type5.3 MediumN/A0%Jun 25, 2026
CVE-2026-49460: Inefficient Algorithmic Complexity3.3 Low5.1 Medium0%Jun 22, 2026
CVE-2026-48788: Improper Neutralization of Input During Web Page Generation8.2 HighN/A0%Jun 17, 2026
CVE-2026-12491: Misinterpretation of Input4.8 MediumN/A0%Jun 17, 2026
CVE-2026-34027: Unrestricted Upload of File with Dangerous TypeN/A5.3 Medium0%Jun 15, 2026
CVE-2026-11526: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Jun 14, 2026
CVE-2026-54394: Improper Limitation of a Pathname to a Restricted DirectoryN/A5.3 Medium0%Jun 12, 2026
26-50 of 592