The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-18049: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 12, 2026
CVE-2026-18048: External Control of File Name or Path7.5 HighN/A0%Aug 12, 2026
CVE-2026-18046: Incorrect Authorization4.3 MediumN/A0%Aug 12, 2026
CVE-2026-18035: Missing Authorization5.3 MediumN/A0%Aug 12, 2026
CVE-2026-17013: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Aug 12, 2026
CVE-2026-16977: Improper Neutralization of Special Elements used in an SQL Command8.1 HighN/A0%Aug 12, 2026
CVE-2026-16737: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Aug 12, 2026
CVE-2026-16538: Improper Access Control9.1 CriticalN/A0%Aug 12, 2026
CVE-2026-16294: Server-Side Request Forgery (SSRF)7.1 HighN/A0%Aug 12, 2026
CVE-2026-16253: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 12, 2026
CVE-2026-16066: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Aug 12, 2026
CVE-2026-16051: Improper Control of Generation of Code9.8 CriticalN/A1%Aug 12, 2026
CVE-2026-15388: Incorrect Authorization4.3 MediumN/A0%Aug 12, 2026
CVE-2026-15249: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Aug 12, 2026
CVE-2026-15039: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Aug 12, 2026
CVE-2026-14925: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 12, 2026
CVE-2026-14859: Improper Access Control4.3 MediumN/A0%Aug 12, 2026
CVE-2026-14858: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Aug 12, 2026
CVE-2026-14857: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Aug 12, 2026
CVE-2026-13613: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Aug 12, 2026
CVE-2026-13612: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Aug 12, 2026
CVE-2026-13177: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Aug 12, 2026
CVE-2026-13171: Improper Access Control8.2 HighN/A0%Aug 12, 2026
CVE-2026-13168: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 12, 2026
CVE-2026-12976: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 12, 2026
22401-22425 of 677876