The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-66398: Download of Code Without Integrity CheckN/A9.4 Critical0%Jul 27, 2026
CVE-2026-66476: Improper Limitation of a Pathname to a Restricted Directory4.9 MediumN/A1%Jul 27, 2026
CVE-2026-66427: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Jul 27, 2026
CVE-2026-59537: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Jul 27, 2026
CVE-2026-59690: Missing Authorization8.0 HighN/A0%Jul 27, 2026
CVE-2026-12989: Missing Authentication for Critical FunctionN/A8.7 High0%Jul 27, 2026
CVE-2026-14856: Improper Neutralization of Input During Web Page GenerationN/A6.3 Medium0%Jul 27, 2026
CVE-2026-12495: Stack-based Buffer OverflowN/A5.3 Medium0%Jul 27, 2026
CVE-2026-14837: Improper Verification of Cryptographic Signature7.8 High8.5 High0%Jul 27, 2026
CVE-2026-14203: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Jul 27, 2026
CVE-2026-14189: Improper Neutralization of Special Elements used in an SQL Command3.8 LowN/A0%Jul 27, 2026
CVE-2026-13597: Improper Authentication9.1 CriticalN/A0%Jul 27, 2026
CVE-2026-13332: Improper Authentication9.1 CriticalN/A0%Jul 27, 2026
CVE-2026-13152: Improper Privilege Management8.1 HighN/A0%Jul 27, 2026
CVE-2026-12394: Improper Privilege Management9.8 CriticalN/A2%Jul 27, 2026
CVE-2026-12255: Improper Authentication8.1 HighN/A0%Jul 27, 2026
CVE-2026-15962: Deserialization of Untrusted Data8.8 HighN/A1%Jul 26, 2026
CVE-2026-66012: Missing Authorization10.0 Critical10.0 Critical1%Jul 25, 2026
CVE-2026-64360: Undefined Security Weakness5.5 MediumN/A0%Jul 25, 2026
CVE-2026-64283: Integer Overflow or Wraparound7.0 HighN/A0%Jul 25, 2026
CVE-2026-55985: Cleartext Storage of Sensitive Information4.3 Medium5.3 Medium0%Jul 24, 2026
CVE-2026-66040: Heap-based Buffer Overflow8.8 High8.7 High1%Jul 24, 2026
CVE-2026-65711: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High2%Jul 24, 2026
CVE-2026-65693: Improper Control of Generation of Code7.2 High8.6 High1%Jul 24, 2026
CVE-2026-64247: Out-of-bounds Read8.4 HighN/A0%Jul 24, 2026
2226-2250 of 17470