The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-9890: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Oct 18, 2025
CVE-2025-5555: Stack-based Buffer Overflow7.8 High7.1 High0%Oct 18, 2025
CVE-2025-11256: Improper Authorization5.3 MediumN/A0%Oct 18, 2025
CVE-2025-10750: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Oct 18, 2025
CVE-2025-40003: Undefined Security WeaknessN/AN/A0%Oct 18, 2025
CVE-2025-40002: Undefined Security WeaknessN/AN/A0%Oct 18, 2025
CVE-2025-40001: Undefined Security WeaknessN/AN/A0%Oct 18, 2025
CVE-2025-9562: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 18, 2025
CVE-2025-11741: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Oct 18, 2025
CVE-2025-11703: Acceptance of Extraneous Untrusted Data With Trusted Data5.3 MediumN/A0%Oct 18, 2025
CVE-2025-11691: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Oct 18, 2025
CVE-2025-11519: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Oct 18, 2025
CVE-2025-11517: Authorization Bypass Through User-Controlled Key7.5 HighN/A0%Oct 18, 2025
CVE-2025-11510: Improper Authorization4.3 MediumN/A0%Oct 18, 2025
CVE-2025-11391: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Oct 18, 2025
CVE-2025-11372: Missing Authorization6.5 MediumN/A0%Oct 18, 2025
CVE-2025-11270: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 18, 2025
CVE-2025-10187: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Oct 18, 2025
CVE-2025-10006: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 18, 2025
CVE-2025-11937: Improper Neutralization of Input During Web Page GenerationN/A6.9 Medium0%Oct 18, 2025
CVE-2025-11857: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 18, 2025
CVE-2025-11742: Missing Authorization4.3 MediumN/A0%Oct 18, 2025
CVE-2025-11738: External Control of File Name or Path5.3 MediumN/A0%Oct 18, 2025
CVE-2025-62671: Improper Neutralization of Input During Web Page GenerationN/A6.9 Medium0%Oct 18, 2025
CVE-2025-62670: Improper Neutralization of Input During Web Page GenerationN/A6.9 Medium0%Oct 18, 2025
83976-84000 of 395320