The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-70340: Improper Access Control6.5 MediumN/A0%Aug 26, 2026
CVE-2025-70293: Heap-based Buffer Overflow9.8 CriticalN/A1%Aug 26, 2026
CVE-2025-70290: Integer Overflow or Wraparound9.8 CriticalN/A1%Aug 26, 2026
CVE-2026-79940: Improper Access Control5.9 MediumN/A0%Aug 26, 2026
CVE-2026-75466: Divide By Zero6.5 MediumN/A0%Aug 26, 2026
CVE-2026-75325: Improper Authentication9.8 CriticalN/A1%Aug 26, 2026
CVE-2026-71171: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A2%Aug 26, 2026
CVE-2026-70419: Improper Neutralization of Special Elements used in an OS Command9.1 CriticalN/A2%Aug 26, 2026
CVE-2026-63179: Improper Limitation of a Pathname to a Restricted Directory4.9 MediumN/A1%Aug 26, 2026
CVE-2026-51106: Uncontrolled Resource Consumption9.3 CriticalN/A0%Aug 26, 2026
CVE-2026-48786: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 26, 2026
CVE-2026-41262: Incorrect Authorization4.3 MediumN/A0%Aug 26, 2026
CVE-2026-36851: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Aug 26, 2026
CVE-2026-19485: Use of Insufficiently Random ValuesN/A9.3 Critical0%Aug 26, 2026
CVE-2025-61165: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A0%Aug 26, 2026
CVE-2025-61164: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 26, 2026
CVE-2025-61163: Permissive Cross-domain Policy with Untrusted Domains9.8 CriticalN/A0%Aug 26, 2026
CVE-2025-61162: Improper Access Control7.5 HighN/A0%Aug 26, 2026
CVE-2026-76784: Missing Cryptographic StepN/A8.7 High0%Aug 26, 2026
CVE-2026-58474: Improper Control of Generation of Code8.8 High8.6 High1%Aug 26, 2026
CVE-2026-54256: Improper Access Control5.4 MediumN/A0%Aug 26, 2026
CVE-2026-47841: Undefined Security Weakness7.4 HighN/A0%Aug 26, 2026
CVE-2026-47837: Missing Authentication for Critical Function9.8 CriticalN/A1%Aug 26, 2026
CVE-2026-47836: Undefined Security Weakness8.1 HighN/A0%Aug 26, 2026
CVE-2026-32639: Authentication Bypass by Alternate Name6.8 MediumN/A0%Aug 26, 2026
15251-15275 of 677876