The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-10580: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 25, 2025
CVE-2025-10488: Improper Limitation of a Pathname to a Restricted Directory8.1 HighN/A0%Oct 25, 2025
CVE-2025-8666: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 25, 2025
CVE-2025-8588: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 25, 2025
CVE-2025-8413: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 25, 2025
CVE-2025-6680: Improper Access Control4.3 MediumN/A0%Oct 25, 2025
CVE-2025-6639: Improper Authorization5.4 MediumN/A0%Oct 25, 2025
CVE-2025-12095: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Oct 25, 2025
CVE-2025-12005: Improper Authorization4.3 MediumN/A0%Oct 25, 2025
CVE-2025-11888: Incorrect Authorization2.7 LowN/A0%Oct 25, 2025
CVE-2025-11879: Improper Authorization6.5 MediumN/A0%Oct 25, 2025
CVE-2025-11564: Missing Authorization5.3 MediumN/A0%Oct 25, 2025
CVE-2025-11269: Missing Authorization5.3 MediumN/A0%Oct 25, 2025
CVE-2025-11244: Improper Authorization3.7 LowN/A0%Oct 25, 2025
CVE-2025-11238: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Oct 25, 2025
CVE-2025-10737: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 25, 2025
CVE-2025-10694: Missing Authorization5.3 MediumN/A0%Oct 25, 2025
CVE-2025-11823: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6.4 MediumN/A0%Oct 25, 2025
CVE-2025-10579: Missing Authorization5.3 MediumN/A0%Oct 25, 2025
CVE-2025-11760: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Oct 25, 2025
CVE-2025-12194: Uncontrolled Resource ConsumptionN/A5.9 Medium0%Oct 24, 2025
CVE-2025-34503: Improper Verification of Cryptographic SignatureN/A7.0 High0%Oct 24, 2025
CVE-2025-34502: Missing Immutable Root of Trust in HardwareN/A7.0 High0%Oct 24, 2025
CVE-2025-34500: Use of Hard-coded Cryptographic KeyN/A7.0 High0%Oct 24, 2025
CVE-2025-62711: Improper Handling of Exceptional Conditions3.1 Low2.1 Low0%Oct 24, 2025
83576-83600 of 614180