The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-61330: Use of Hard-coded Password6.5 MediumN/A0%Oct 16, 2025
CVE-2025-60641: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Oct 16, 2025
CVE-2025-60639: Use of Hard-coded Credentials6.5 MediumN/A0%Oct 16, 2025
CVE-2025-34512: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Oct 16, 2025
CVE-2025-34517: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High1%Oct 16, 2025
CVE-2025-34514: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High2%Oct 16, 2025
CVE-2025-34519: Use of a Broken or Risky Cryptographic Algorithm7.5 High8.2 High0%Oct 16, 2025
CVE-2025-34518: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High1%Oct 16, 2025
CVE-2025-34515: Execution with Unnecessary Privileges9.8 Critical9.3 Critical8%Oct 16, 2025
CVE-2025-34513: Improper Neutralization of Special Elements used in an OS Command9.8 Critical9.3 Critical8%Oct 16, 2025
CVE-2025-34516: Use of Default Credentials9.8 Critical9.3 Critical1%Oct 16, 2025
CVE-2025-61789: Observable Response Discrepancy5.3 MediumN/A0%Oct 16, 2025
CVE-2025-58051: Improper Enforcement of Behavioral Workflow6.5 MediumN/A1%Oct 16, 2025
CVE-2025-56700: Improper Neutralization of Special Elements used in an SQL Command5.4 MediumN/A0%Oct 16, 2025
CVE-2025-56699: Improper Neutralization of Special Elements used in an SQL Command5.4 MediumN/A0%Oct 16, 2025
CVE-2025-53092: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Oct 16, 2025
CVE-2025-36128: Missing Release of Resource after Effective Lifetime7.5 HighN/A1%Oct 16, 2025
CVE-2025-25298: Weak Encoding for Password5.3 Medium6.3 Medium0%Oct 16, 2025
CVE-2025-11854: Undefined Security WeaknessN/AN/AN/AOct 16, 2025
CVE-2025-9559: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Oct 16, 2025
CVE-2025-62496: Integer Overflow or Wraparound8.8 High7.1 High0%Oct 16, 2025
CVE-2025-62495: Integer Underflow (Wrap or Wraparound)8.8 High7.1 High0%Oct 16, 2025
CVE-2025-62494: Incorrect Type Conversion or Cast8.8 High7.1 High1%Oct 16, 2025
CVE-2025-62493: Out-of-bounds Read6.5 Medium5.9 Medium0%Oct 16, 2025
CVE-2025-62492: Out-of-bounds Read6.5 Medium5.9 Medium0%Oct 16, 2025
84076-84100 of 764060