The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-6893: Execution with Unnecessary PrivilegesN/A9.3 Critical1%Oct 17, 2025
CVE-2025-6892: Incorrect AuthorizationN/A8.7 High1%Oct 17, 2025
CVE-2025-62506: Incorrect Authorization8.1 HighN/A1%Oct 16, 2025
CVE-2025-62504: Use After Free6.5 MediumN/A0%Oct 16, 2025
CVE-2025-11896: Uncontrolled RecursionN/A2.1 Low0%Oct 16, 2025
CVE-2025-11864: Server-Side Request Forgery (SSRF)7.3 High6.9 Medium0%Oct 16, 2025
CVE-2024-42192: Insufficiently Protected Credentials5.5 MediumN/A0%Oct 16, 2025
CVE-2025-61554: Divide By Zero5.5 MediumN/A0%Oct 16, 2025
CVE-2025-60358: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Oct 16, 2025
CVE-2025-62428: URL Redirection to Untrusted SiteN/A8.8 High0%Oct 16, 2025
CVE-2025-62427: Server-Side Request Forgery (SSRF)N/A8.7 High0%Oct 16, 2025
CVE-2025-62425: Unverified Password Change8.3 HighN/A0%Oct 16, 2025
CVE-2025-62423: Improper Neutralization of Special Elements used in an SQL Command6.7 MediumN/A1%Oct 16, 2025
CVE-2025-62418: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6.9 MediumN/A0%Oct 16, 2025
CVE-2025-62417: Improper Neutralization of Formula Elements in a CSV File7.8 High7.1 High0%Oct 16, 2025
CVE-2025-62416: Improper Control of Generation of Code5.1 MediumN/A0%Oct 16, 2025
CVE-2025-62415: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6.9 MediumN/A0%Oct 16, 2025
CVE-2025-62414: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6.9 MediumN/A0%Oct 16, 2025
CVE-2025-61553: Heap-based Buffer Overflow8.2 HighN/A0%Oct 16, 2025
CVE-2025-61514: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A0%Oct 16, 2025
CVE-2025-60855: Improper Neutralization of Special Elements used in a Command5.1 MediumN/A0%Oct 16, 2025
CVE-2025-11853: Improper Access Control6.3 Medium2.1 Low0%Oct 16, 2025
CVE-2025-11852: Missing Authentication for Critical Function5.3 Medium5.5 Medium1%Oct 16, 2025
CVE-2025-11493: Download of Code Without Integrity Check8.8 HighN/A0%Oct 16, 2025
CVE-2025-11492: Cleartext Transmission of Sensitive Information9.6 CriticalN/A0%Oct 16, 2025
84051-84075 of 764060