The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-10939: Uncontrolled Search Path Element3.7 LowN/A0%Oct 28, 2025
CVE-2025-12347: Unrestricted Upload of File with Dangerous Type6.3 Medium2.1 Low0%Oct 28, 2025
CVE-2025-12346: Unrestricted Upload of File with Dangerous Type6.3 Medium2.1 Low0%Oct 28, 2025
CVE-2025-12344: Unrestricted Upload of File with Dangerous Type6.3 Medium2.1 Low0%Oct 28, 2025
CVE-2025-12342: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 28, 2025
CVE-2025-12341: Improper Link Resolution Before File Access7.8 High7.1 High0%Oct 28, 2025
CVE-2025-12339: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 28, 2025
CVE-2025-12338: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 28, 2025
CVE-2025-12337: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 28, 2025
CVE-2025-12336: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 28, 2025
CVE-2025-43024: Exposure of Sensitive System Information to an Unauthorized Control Sphere7.5 High5.1 Medium0%Oct 28, 2025
CVE-2025-33133: Out-of-bounds Write6.5 MediumN/A0%Oct 28, 2025
CVE-2025-33132: Use of sizeof() on a Pointer Type6.5 MediumN/A0%Oct 28, 2025
CVE-2025-33131: Buffer Copy without Checking Size of Input6.5 MediumN/A0%Oct 28, 2025
CVE-2025-33126: Incorrect Calculation of Buffer Size6.5 MediumN/A0%Oct 28, 2025
CVE-2025-12335: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Oct 28, 2025
CVE-2025-12332: Improper Neutralization of Input During Web Page Generation2.4 Low1.9 Low0%Oct 28, 2025
CVE-2025-56399: Improper Control of Generation of CodeN/AN/A1%Oct 28, 2025
CVE-2025-60349: Uncontrolled Resource ConsumptionN/AN/A0%Oct 28, 2025
CVE-2025-62259: Incorrect Authorization5.4 Medium6.9 Medium0%Oct 27, 2025
CVE-2025-62258: Cross-Site Request Forgery (CSRF)6.5 Medium7.0 High0%Oct 27, 2025
CVE-2025-12334: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Oct 27, 2025
CVE-2025-12333: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Oct 27, 2025
CVE-2025-62793: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Oct 27, 2025
CVE-2025-62781: Insufficient Session Expiration5.0 MediumN/A0%Oct 27, 2025
83526-83550 of 580342