The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-62232: Insertion of Sensitive Information into Log File7.5 HighN/A0%Oct 31, 2025
CVE-2025-30191: Improper Restriction of Rendered UI Layers or Frames5.4 MediumN/A0%Oct 31, 2025
CVE-2025-30189: Improper Preservation of Consistency Between Independent Representations of Shared State7.4 HighN/A0%Oct 31, 2025
CVE-2025-30188: Uncontrolled Resource Consumption7.5 HighN/A0%Oct 31, 2025
CVE-2025-12175: Missing Authorization4.3 MediumN/A0%Oct 31, 2025
CVE-2025-12094: Protection Mechanism Failure5.3 MediumN/A0%Oct 31, 2025
CVE-2025-8385: Improper Limitation of a Pathname to a Restricted Directory6.8 MediumN/A0%Oct 31, 2025
CVE-2025-6520: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Oct 31, 2025
CVE-2025-10897: Improper Limitation of a Pathname to a Restricted Directory8.6 HighN/A0%Oct 31, 2025
CVE-2025-8489: Improper Privilege Management9.8 CriticalN/A39%Oct 31, 2025
CVE-2025-7846: Absolute Path Traversal8.8 HighN/A0%Oct 31, 2025
CVE-2025-63675: Deserialization of Untrusted Data6.9 MediumN/A0%Oct 31, 2025
CVE-2025-5397: Authentication Bypass Using an Alternate Path or Channel9.8 CriticalN/A0%Oct 31, 2025
CVE-2025-58152: Files or Directories Accessible to External Parties5.3 Medium6.9 Medium0%Oct 31, 2025
CVE-2025-54763: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High0%Oct 31, 2025
CVE-2025-11191: Missing Authorization5.3 MediumN/A0%Oct 31, 2025
CVE-2025-11975: Missing Authorization4.3 MediumN/A0%Oct 31, 2025
CVE-2025-11806: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 31, 2025
CVE-2025-23050: Out-of-bounds Read3.1 LowN/A0%Oct 31, 2025
CVE-2025-8849: Uncontrolled Resource Consumption7.5 HighN/A0%Oct 31, 2025
CVE-2025-6176: Uncontrolled Resource Consumption7.5 HighN/A0%Oct 31, 2025
CVE-2025-52665: Missing Authentication for Critical Function10.0 CriticalN/A11%Oct 31, 2025
CVE-2025-52664: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Oct 31, 2025
CVE-2025-52663: Active Debug Code7.3 HighN/A0%Oct 31, 2025
CVE-2025-48984: Improper Control of Generation of Code8.8 HighN/A0%Oct 31, 2025
83176-83200 of 813908