The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-18201: Missing Authorization5.5 MediumN/A0%Jul 29, 2026
CVE-2026-9720: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Jul 29, 2026
CVE-2026-18191: Hidden Functionality9.8 Critical9.3 Critical1%Jul 29, 2026
CVE-2026-63238: Improper Authentication6.5 MediumN/A0%Jul 29, 2026
CVE-2026-63237: Improper Verification of Cryptographic Signature4.8 MediumN/A0%Jul 29, 2026
CVE-2026-14300: Improper Authentication8.1 HighN/A0%Jul 29, 2026
CVE-2026-14234: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Jul 29, 2026
CVE-2026-14224: Authorization Bypass Through User-Controlled Key5.4 MediumN/A0%Jul 29, 2026
CVE-2026-13605: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Jul 29, 2026
CVE-2026-13423: Improper Control of Generation of Code9.8 CriticalN/A1%Jul 29, 2026
CVE-2026-18072: Embedded Malicious Code9.8 CriticalN/A3%Jul 29, 2026
CVE-2026-15344: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A1%Jul 29, 2026
CVE-2026-12144: Improper Privilege Management8.8 HighN/A1%Jul 29, 2026
CVE-2026-14446: Missing Authentication for Critical Function9.8 CriticalN/A1%Jul 28, 2026
CVE-2026-16347: Improper Restriction of Excessive Authentication Attempts8.8 High8.7 High0%Jul 28, 2026
CVE-2026-66745: Improper Control of Generation of Code7.5 High7.5 High1%Jul 28, 2026
CVE-2026-5114: Improper Limitation of a Pathname to a Restricted Directory4.9 MediumN/A0%Jul 28, 2026
CVE-2026-4912: Server-Side Request Forgery (SSRF)4.1 MediumN/A0%Jul 28, 2026
CVE-2026-15992: Improper Privilege Management8.8 HighN/A1%Jul 28, 2026
CVE-2026-7868: Incorrect Authorization6.5 MediumN/A0%Jul 28, 2026
CVE-2026-61609: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Jul 28, 2026
CVE-2026-15444: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Jul 28, 2026
CVE-2026-15025: Missing Authorization7.5 HighN/A1%Jul 28, 2026
CVE-2026-63301: Client-Side Enforcement of Server-Side SecurityN/A7.0 High1%Jul 28, 2026
CVE-2026-14328: Improper Privilege Management8.8 HighN/A1%Jul 28, 2026
2176-2200 of 17465