The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-19566: Improper Validation of Specified Quantity in Input7.5 HighN/A1%Aug 12, 2026
CVE-2026-19426: Missing Authentication for Critical Function8.2 High8.8 High1%Aug 12, 2026
CVE-2025-41771: Improper Neutralization of Special Elements used in an SQL Command4.3 Medium5.3 Medium0%Aug 12, 2026
CVE-2025-41770: Allocation of Resources Without Limits or Throttling7.5 High8.7 High1%Aug 12, 2026
CVE-2025-41769: Buffer Copy without Checking Size of Input9.8 Critical9.3 Critical1%Aug 12, 2026
CVE-2026-66659: Improper Neutralization of Special Elements used in an SQL Command9.3 CriticalN/A0%Aug 12, 2026
CVE-2026-19594: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A0%Aug 12, 2026
CVE-2026-19217: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Aug 12, 2026
CVE-2026-19073: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Aug 12, 2026
CVE-2026-19052: Missing Authorization4.3 MediumN/A0%Aug 12, 2026
CVE-2026-19050: Server-Side Request Forgery (SSRF)6.4 MediumN/A0%Aug 12, 2026
CVE-2026-18962: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Aug 12, 2026
CVE-2026-18943: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 12, 2026
CVE-2026-18789: Missing Authorization7.5 HighN/A0%Aug 12, 2026
CVE-2026-18474: Improper Neutralization of Special Elements used in an SQL Command8.6 HighN/A0%Aug 12, 2026
CVE-2026-18391: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Aug 12, 2026
CVE-2026-18366: Improper Privilege Management9.8 CriticalN/A0%Aug 12, 2026
CVE-2026-18230: Improper Neutralization of Special Elements used in an SQL Command8.1 HighN/A0%Aug 12, 2026
CVE-2026-18057: Improper Neutralization of Special Elements used in an SQL Command8.1 HighN/A0%Aug 12, 2026
CVE-2026-18049: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 12, 2026
CVE-2026-18048: External Control of File Name or Path7.5 HighN/A0%Aug 12, 2026
CVE-2026-18046: Incorrect Authorization4.3 MediumN/A0%Aug 12, 2026
CVE-2026-18035: Missing Authorization5.3 MediumN/A0%Aug 12, 2026
CVE-2026-17013: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Aug 12, 2026
CVE-2026-16977: Improper Neutralization of Special Elements used in an SQL Command8.1 HighN/A0%Aug 12, 2026
22376-22400 of 677876