The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-18473: Improper Neutralization of Special Elements used in an SQL Command9.1 CriticalN/A0%Aug 9, 2026
CVE-2026-18465: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Aug 9, 2026
CVE-2026-18464: Uncontrolled Resource Consumption7.5 HighN/A0%Aug 9, 2026
CVE-2026-18357: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 9, 2026
CVE-2026-18037: Missing Authorization6.5 MediumN/A0%Aug 9, 2026
CVE-2026-18032: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 9, 2026
CVE-2026-17044: Improper Neutralization of Special Elements used in an SQL Command8.6 HighN/A0%Aug 9, 2026
CVE-2026-17017: Improper Neutralization of Special Elements used in an SQL Command8.1 HighN/A0%Aug 9, 2026
CVE-2026-17014: External Control of File Name or Path5.3 MediumN/A0%Aug 9, 2026
CVE-2026-17011: Insufficient Verification of Data Authenticity3.8 LowN/A0%Aug 9, 2026
CVE-2026-16992: Missing Authorization6.5 MediumN/A0%Aug 9, 2026
CVE-2026-16988: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 9, 2026
CVE-2026-16965: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Aug 9, 2026
CVE-2026-16957: Authorization Bypass Through User-Controlled Key2.7 LowN/A0%Aug 9, 2026
CVE-2026-16032: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Aug 9, 2026
CVE-2026-15038: Improper Authentication9.8 CriticalN/A1%Aug 9, 2026
CVE-2026-19334: Improper Neutralization of Special Elements used in a Command5.3 Medium1.9 Low1%Aug 9, 2026
CVE-2026-19333: Improper Neutralization of Special Elements used in a Command5.3 Medium1.9 Low1%Aug 9, 2026
CVE-2026-19332: Improper Neutralization of Special Elements used in a Command5.3 Medium1.9 Low1%Aug 9, 2026
CVE-2026-19331: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium1.9 Low0%Aug 9, 2026
CVE-2026-19330: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium1.9 Low0%Aug 9, 2026
CVE-2026-19329: Improper Neutralization of Special Elements used in a Command5.3 Medium1.9 Low1%Aug 9, 2026
CVE-2026-10595: Relative Path Traversal7.5 HighN/A1%Aug 9, 2026
CVE-2026-19328: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium1.9 Low0%Aug 9, 2026
CVE-2026-19327: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium1.9 Low0%Aug 9, 2026
24276-24300 of 764060