The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-18673: Exposure of Sensitive Information to an Unauthorized ActorN/A5.3 Medium0%Aug 12, 2026
CVE-2026-8667: Incorrect Authorization4.3 MediumN/A0%Aug 12, 2026
CVE-2026-7427: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Aug 12, 2026
CVE-2026-73327: Undefined Security WeaknessN/A8.7 High1%Aug 12, 2026
CVE-2026-73300: Improper Neutralization of Special Elements used in an SQL Command9.6 CriticalN/A1%Aug 12, 2026
CVE-2026-73299: Improper Control of Generation of Code10.0 CriticalN/A2%Aug 12, 2026
CVE-2026-73298: Authorization Bypass Through User-Controlled KeyN/A8.7 High1%Aug 12, 2026
CVE-2026-69106: Improper Input Validation8.8 HighN/A1%Aug 12, 2026
CVE-2026-49467: Incorrect Implementation of Authentication Algorithm8.8 HighN/A1%Aug 12, 2026
CVE-2026-44741: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A1%Aug 12, 2026
CVE-2026-42018: Improper Authentication7.5 HighN/A10%Aug 12, 2026
CVE-2026-18713: Improper Privilege Management8.8 HighN/A1%Aug 12, 2026
CVE-2026-18669: Execution with Unnecessary Privileges8.8 HighN/A1%Aug 12, 2026
CVE-2026-18250: Concurrent Execution using Shared Resource with Improper Synchronization5.0 MediumN/A0%Aug 12, 2026
CVE-2026-18244: Missing Authorization4.3 MediumN/A0%Aug 12, 2026
CVE-2026-18235: Improper Neutralization of Special Elements used in an OS Command8.3 HighN/A1%Aug 12, 2026
CVE-2026-17420: Improper Neutralization of Special Elements used in an OS Command6.3 MediumN/A0%Aug 12, 2026
CVE-2026-17419: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Aug 12, 2026
CVE-2026-17418: Improper Neutralization of Special Elements used in an SQL Command7.8 HighN/A0%Aug 12, 2026
CVE-2026-17276: Improper Privilege Management9.9 CriticalN/A0%Aug 12, 2026
CVE-2026-17271: Allocation of Resources Without Limits or Throttling7.5 HighN/A1%Aug 12, 2026
CVE-2026-17268: Authentication Bypass by Capture-replay6.8 MediumN/A0%Aug 12, 2026
CVE-2026-17266: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Aug 12, 2026
CVE-2026-17248: Improper Neutralization of Special Elements used in an OS Command6.5 MediumN/A0%Aug 12, 2026
CVE-2026-17222: Improper Neutralization of Special Elements used in an SQL Command4.3 MediumN/A0%Aug 12, 2026
22151-22175 of 576436