The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-62144: Improper Authentication9.1 CriticalN/A1%Jul 22, 2026
CVE-2026-50252: Acceptance of Extraneous Untrusted Data With Trusted Data9.3 Critical5.7 Medium0%Jul 22, 2026
CVE-2026-16232: Improper Authentication9.8 Critical9.3 Critical78%Jul 22, 2026
CVE-2026-55991: Signed to Unsigned Conversion Error5.9 MediumN/A0%Jul 22, 2026
CVE-2026-65603: Improper Privilege Management8.8 High8.7 High0%Jul 22, 2026
CVE-2026-65595: Improper Privilege Management8.8 High8.9 High1%Jul 22, 2026
CVE-2026-65016: Authorization Bypass Through User-Controlled Key8.8 High7.7 High0%Jul 22, 2026
CVE-2026-12968: Improper Neutralization of Input During Web Page Generation8.8 HighN/A1%Jul 22, 2026
CVE-2026-63142: Incorrect Authorization5.0 MediumN/A0%Jul 21, 2026
CVE-2026-60701: Improper Access Control6.6 MediumN/A0%Jul 21, 2026
CVE-2026-60166: Protection Mechanism Failure3.1 LowN/A0%Jul 21, 2026
CVE-2026-60164: Protection Mechanism Failure3.1 LowN/A0%Jul 21, 2026
CVE-2026-47059: Improper Access Control3.7 LowN/A0%Jul 21, 2026
CVE-2026-47035: Improper Access Control3.1 LowN/A0%Jul 21, 2026
CVE-2026-47034: Improper Access Control3.1 LowN/A0%Jul 21, 2026
CVE-2026-47030: Improper Access Control3.1 LowN/A0%Jul 21, 2026
CVE-2026-10674: Reachable Assertion5.5 MediumN/A0%Jul 21, 2026
CVE-2026-8982: Use of Hard-coded Credentials8.1 High10.0 Critical0%Jul 21, 2026
CVE-2026-63092: Missing Authorization4.3 Medium5.3 Medium0%Jul 21, 2026
CVE-2026-47689: Improper Neutralization of Input During Web Page Generation5.2 MediumN/A0%Jul 21, 2026
CVE-2026-47687: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Jul 21, 2026
CVE-2026-47685: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Jul 21, 2026
CVE-2026-47405: Improper Access Control8.8 HighN/A1%Jul 21, 2026
CVE-2026-15724: Improper Limitation of a Pathname to a Restricted Directory8.7 HighN/A1%Jul 21, 2026
CVE-2026-28321: Improper Access Control9.1 CriticalN/A1%Jul 21, 2026
2301-2325 of 17475