The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-71848: Inefficient Algorithmic Complexity5.3 MediumN/A1%Aug 7, 2026
CVE-2026-71847: Use After FreeN/A8.7 High0%Aug 7, 2026
CVE-2026-70561: Authorization Bypass Through User-Controlled Key6.5 Medium7.1 High0%Aug 7, 2026
CVE-2026-69127: Exposure of Sensitive System Information to an Unauthorized Control SphereN/A6.9 Medium1%Aug 7, 2026
CVE-2026-66000: Incorrect AuthorizationN/A2.3 Low0%Aug 7, 2026
CVE-2026-48098: Improper Neutralization of Special Elements used in an OS Command7.3 HighN/A0%Aug 7, 2026
CVE-2026-48097: Improper Neutralization of Special Elements used in an OS Command7.8 HighN/A0%Aug 7, 2026
CVE-2026-19231: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Aug 7, 2026
CVE-2026-19230: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Aug 7, 2026
CVE-2026-17435: Improper Link Resolution Before File Access2.5 LowN/A0%Aug 7, 2026
CVE-2026-11430: Incorrect Implementation of Authentication Algorithm7.3 High6.9 Medium1%Aug 7, 2026
CVE-2025-71413: Improper Check for Unusual or Exceptional Conditions5.3 Medium6.0 Medium0%Aug 7, 2026
CVE-2025-71412: Improper Check for Unusual or Exceptional Conditions7.1 High7.1 High0%Aug 7, 2026
CVE-2025-71411: Allocation of Resources Without Limits or Throttling5.3 Medium6.0 Medium0%Aug 7, 2026
CVE-2025-71410: Allocation of Resources Without Limits or Throttling5.3 Medium6.0 Medium0%Aug 7, 2026
CVE-2025-71409: Missing Authentication for Critical Function7.1 High7.1 High0%Aug 7, 2026
CVE-2025-63235: Uncontrolled Resource Consumption7.5 HighN/A1%Aug 7, 2026
CVE-2026-66058: Missing AuthorizationN/A5.3 Medium0%Aug 7, 2026
CVE-2026-64638: Improper Neutralization of Input During Web Page GenerationN/A8.9 High1%Aug 7, 2026
CVE-2026-64637: Improper Privilege Management9.9 CriticalN/A0%Aug 7, 2026
CVE-2026-64636: Improper Neutralization of Special Elements used in an SQL Command7.7 HighN/A0%Aug 7, 2026
CVE-2026-56818: Missing Release of Memory after Effective Lifetime6.5 MediumN/A0%Aug 7, 2026
CVE-2026-47364: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Aug 7, 2026
CVE-2026-47363: Improper Export of Android Application Components6.3 MediumN/A0%Aug 7, 2026
CVE-2026-47362: Insecure Storage of Sensitive Information4.6 MediumN/A0%Aug 7, 2026
24376-24400 of 764060