The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report
Rapid7

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-16232:Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
CVE-2026-63030:wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-58644:Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
CVE-2026-15409:Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
CVE-2026-35273:Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
CVE-2026-10520:, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry
TitleEitWModules
CVE-2026-45623: postcss: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract…7.5 HighN/A1%Jul 27, 2026
CVE-2026-61246: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60455: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60439: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60373: Improper Privilege Management8.8 HighN/A0%Jul 22, 2026
CVE-2026-60372: Improper Privilege Management9.8 CriticalN/A0%Jul 22, 2026
CVE-2026-60371: Exposure of Sensitive Information to an Unauthorized Actor8.0 HighN/A0%Jul 22, 2026
CVE-2026-60370: Improper Restriction of Rendered UI Layers or Frames7.5 HighN/A0%Jul 22, 2026
CVE-2026-60369: Improper Privilege Management9.9 CriticalN/A0%Jul 22, 2026
CVE-2026-60368: Use of Unmaintained Third Party Components8.8 HighN/A0%Jul 22, 2026
CVE-2026-60367: Improper Privilege Management9.8 CriticalN/A0%Jul 22, 2026
CVE-2026-60366: Improper Privilege Management10.0 CriticalN/A0%Jul 22, 2026
CVE-2026-16607: Improper Privilege Management7.8 High8.5 High0%Jul 22, 2026
CVE-2026-16606: Improper Control of Generation of Code9.8 Critical9.3 Critical1%Jul 22, 2026
CVE-2026-13182: Generation of Error Message Containing Sensitive Information7.5 HighN/A0%Jul 22, 2026
CVE-2026-62574: Improper Access Control7.8 HighN/A0%Jul 21, 2026
CVE-2026-62567: Exposure of Sensitive Information to an Unauthorized Actor7.7 HighN/A0%Jul 21, 2026
CVE-2026-62565: Exposure of Sensitive Information to an Unauthorized Actor7.1 HighN/A0%Jul 21, 2026
CVE-2026-62563: Improper Authorization5.4 MediumN/A0%Jul 21, 2026
CVE-2026-62562: Improper Access Control6.5 MediumN/A0%Jul 21, 2026
CVE-2026-62561: Improper Privilege Management7.8 HighN/A0%Jul 21, 2026
CVE-2026-62560: Exposure of Sensitive Information to an Unauthorized Actor7.7 HighN/A0%Jul 21, 2026
CVE-2026-62559: Exposure of Sensitive Information to an Unauthorized Actor6.8 MediumN/A0%Jul 21, 2026
CVE-2026-62557: Improper Access Control7.1 HighN/A0%Jul 21, 2026
CVE-2026-62556: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Jul 21, 2026
1-25 of 10672