The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-8414: Improper Input ValidationN/A9.4 Critical0%Oct 17, 2025
CVE-2025-62356: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Oct 17, 2025
CVE-2025-62353: Improper Limitation of a Pathname to a Restricted Directory9.8 CriticalN/A1%Oct 17, 2025
CVE-2025-60279: Server-Side Request Forgery (SSRF)9.6 CriticalN/A0%Oct 17, 2025
CVE-2025-59043: Uncontrolled Resource Consumption7.5 HighN/A1%Oct 17, 2025
CVE-2025-58747: Improper Neutralization of Input During Web Page Generation6.1 Medium2.0 Low6%Oct 17, 2025
CVE-2025-57567: Improper Control of Generation of Code9.1 CriticalN/A1%Oct 17, 2025
CVE-2025-49655: Deserialization of Untrusted Data9.8 CriticalN/A1%Oct 17, 2025
CVE-2025-26625: Improper Link Resolution Before File AccessN/A8.6 High1%Oct 17, 2025
CVE-2025-11905: Improper Control of Generation of Code6.3 Medium2.1 Low1%Oct 17, 2025
CVE-2025-60361: Missing Release of Memory after Effective Lifetime3.3 LowN/A0%Oct 17, 2025
CVE-2025-55085: Out-of-bounds Read7.5 High8.8 High1%Oct 17, 2025
CVE-2025-48087: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Oct 17, 2025
CVE-2025-11904: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low1%Oct 17, 2025
CVE-2025-60360: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Oct 17, 2025
CVE-2025-60359: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Oct 17, 2025
CVE-2025-48044: Incorrect AuthorizationN/A8.6 High1%Oct 17, 2025
CVE-2025-11903: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low1%Oct 17, 2025
CVE-2025-11902: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low1%Oct 17, 2025
CVE-2023-28815: Improper Neutralization of Parameter/Argument Delimiters9.8 CriticalN/A1%Oct 17, 2025
CVE-2023-28814: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Oct 17, 2025
CVE-2025-11895: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Oct 17, 2025
CVE-2025-55100: Out-of-bounds Read9.1 Critical2.4 Low1%Oct 17, 2025
CVE-2025-55099: Out-of-bounds Read6.1 Medium2.4 Low0%Oct 17, 2025
CVE-2025-55098: Out-of-bounds Read6.1 Medium1.0 Low0%Oct 17, 2025
84026-84050 of 764060