The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-40011: Undefined Security WeaknessN/AN/A0%Oct 20, 2025
CVE-2025-40010: Undefined Security WeaknessN/AN/A0%Oct 20, 2025
CVE-2025-40009: Undefined Security WeaknessN/AN/A0%Oct 20, 2025
CVE-2025-40008: Undefined Security WeaknessN/AN/A0%Oct 20, 2025
CVE-2025-40007: Undefined Security WeaknessN/AN/A0%Oct 20, 2025
CVE-2025-40006: Undefined Security Weakness7.8 HighN/A0%Oct 20, 2025
CVE-2025-8884: Authorization Bypass Through User-Controlled Key5.5 MediumN/A0%Oct 20, 2025
CVE-2025-61456: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 20, 2025
CVE-2025-61417: Improper Neutralization of Input During Web Page Generation8.8 HighN/A1%Oct 20, 2025
CVE-2025-57738: Improper Isolation or Compartmentalization7.2 HighN/A23%Oct 20, 2025
CVE-2025-54957: Integer Overflow or Wraparound9.8 CriticalN/A2%Oct 20, 2025
CVE-2025-41390: Inclusion of Functionality from Untrusted Control Sphere7.8 HighN/A0%Oct 20, 2025
CVE-2025-61455: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A1%Oct 20, 2025
CVE-2025-11680: Out-of-bounds WriteN/A5.9 Medium0%Oct 20, 2025
CVE-2025-11679: Out-of-bounds ReadN/A5.9 Medium0%Oct 20, 2025
CVE-2025-11678: Stack-based Buffer OverflowN/A7.5 High0%Oct 20, 2025
CVE-2025-11677: Use After FreeN/A6.3 Medium0%Oct 20, 2025
CVE-2025-61454: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 20, 2025
CVE-2025-56224: Improper Restriction of Excessive Authentication Attempts8.1 HighN/A0%Oct 20, 2025
CVE-2025-56223: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Oct 20, 2025
CVE-2025-56219: Improper Access Control7.1 HighN/A0%Oct 20, 2025
CVE-2025-8349: Improper Neutralization of Input During Web Page GenerationN/A5.3 Medium1%Oct 20, 2025
CVE-2025-57837: Exposure of Sensitive Information to an Unauthorized Actor2.9 LowN/A0%Oct 20, 2025
CVE-2025-41028: Improper Neutralization of Special Elements used in an SQL CommandN/A9.3 Critical0%Oct 20, 2025
CVE-2025-61932: Improper Verification of Source of a Communication Channel9.8 Critical9.3 Critical3%Oct 20, 2025
83951-83975 of 400222