The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-72569: Improper Limitation of a Pathname to a Restricted Directory9.1 CriticalN/A1%Aug 10, 2026
CVE-2026-72568: Undefined Security WeaknessN/AN/A0%Aug 10, 2026
CVE-2026-72567: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A1%Aug 10, 2026
CVE-2026-72566: Server-Side Request Forgery (SSRF)7.7 HighN/A0%Aug 10, 2026
CVE-2026-72565: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Aug 10, 2026
CVE-2026-72564: Authorization Bypass Through User-Controlled Key9.6 CriticalN/A0%Aug 10, 2026
CVE-2026-71394: Improper Validation of Specified Quantity in InputN/A5.3 Medium0%Aug 10, 2026
CVE-2026-71393: Integer Overflow or WraparoundN/A5.3 Medium1%Aug 10, 2026
CVE-2026-71392: Integer Overflow or WraparoundN/A5.3 Medium1%Aug 10, 2026
CVE-2026-71391: Off-by-one ErrorN/A5.3 Medium1%Aug 10, 2026
CVE-2026-66642: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Aug 10, 2026
CVE-2026-66486: Improper Encoding or Escaping of OutputN/A4.6 Medium0%Aug 10, 2026
CVE-2026-66485: Memory Allocation with Excessive Size ValueN/A4.6 Medium0%Aug 10, 2026
CVE-2026-66484: Improper Limitation of a Pathname to a Restricted DirectoryN/A4.6 Medium0%Aug 10, 2026
CVE-2026-65948: Improper Restriction of Excessive Authentication Attempts7.3 HighN/A1%Aug 10, 2026
CVE-2026-65945: Insertion of Sensitive Information into Log File6.5 MediumN/A1%Aug 10, 2026
CVE-2026-65942: Improper Validation of Certificate with Host Mismatch7.5 HighN/A1%Aug 10, 2026
CVE-2026-61899: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A1%Aug 10, 2026
CVE-2026-59087: Out-of-bounds Write7.8 HighN/A0%Aug 10, 2026
CVE-2026-55814: Missing Authentication for Critical Function7.5 HighN/A1%Aug 10, 2026
CVE-2026-55799: Improper Control of Generation of Code9.8 CriticalN/A1%Aug 10, 2026
CVE-2026-44416: Improper Control of Generation of Code9.8 CriticalN/A1%Aug 10, 2026
CVE-2026-42537: Improper Control of Generation of Code9.8 CriticalN/A1%Aug 10, 2026
CVE-2026-40920: Improper Privilege Management9.8 CriticalN/A1%Aug 10, 2026
CVE-2026-32227: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Aug 10, 2026
24176-24200 of 401423