The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-16955: Improper Limitation of a Pathname to a Restricted Directory5.0 MediumN/A0%Aug 8, 2026
CVE-2026-16953: Authorization Bypass Through User-Controlled Key4.8 MediumN/A0%Aug 8, 2026
CVE-2026-16948: Improper Access Control8.1 HighN/A0%Aug 8, 2026
CVE-2026-16608: Missing Authorization5.3 MediumN/A0%Aug 8, 2026
CVE-2026-16595: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 8, 2026
CVE-2026-16594: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 8, 2026
CVE-2026-16590: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 8, 2026
CVE-2026-16589: Improper Neutralization of Special Elements used in an SQL Command7.7 HighN/A0%Aug 8, 2026
CVE-2026-16578: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Aug 8, 2026
CVE-2026-16574: Authorization Bypass Through User-Controlled Key5.4 MediumN/A0%Aug 8, 2026
CVE-2026-16562: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 8, 2026
CVE-2026-16559: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Aug 8, 2026
CVE-2026-16558: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Aug 8, 2026
CVE-2026-16535: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Aug 8, 2026
CVE-2026-16282: Improper Authentication5.3 MediumN/A0%Aug 8, 2026
CVE-2026-16269: Improper Authentication4.8 MediumN/A0%Aug 8, 2026
CVE-2026-16267: Deserialization of Untrusted Data8.1 HighN/A0%Aug 8, 2026
CVE-2026-14526: Improper Privilege Management9.8 CriticalN/A1%Aug 8, 2026
CVE-2026-18988: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Aug 8, 2026
CVE-2026-13505: Missing Release of Resource after Effective LifetimeN/A8.7 High0%Aug 8, 2026
CVE-2026-8798: Loop with Unreachable Exit ConditionN/A8.7 High0%Aug 8, 2026
CVE-2026-52880: Uncontrolled Resource Consumption7.5 HighN/A0%Aug 7, 2026
CVE-2026-52879: Uncontrolled Resource Consumption7.5 HighN/A0%Aug 7, 2026
CVE-2026-52878: NULL Pointer Dereference7.5 HighN/A0%Aug 7, 2026
CVE-2026-49343: Uncontrolled Resource Consumption5.9 MediumN/A0%Aug 7, 2026
24326-24350 of 764060