The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-10706: Missing Authorization8.8 HighN/A1%Oct 16, 2025
CVE-2025-58778: Hidden Functionality7.2 High8.6 High1%Oct 16, 2025
CVE-2025-0275: Missing Authentication for Critical Function5.3 MediumN/A0%Oct 16, 2025
CVE-2025-11814: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Oct 16, 2025
CVE-2025-0274: Missing Authentication for Critical Function5.3 MediumN/A0%Oct 16, 2025
CVE-2025-10700: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Oct 16, 2025
CVE-2025-62580: Stack-based Buffer Overflow7.8 HighN/A0%Oct 16, 2025
CVE-2025-62579: Stack-based Buffer Overflow7.8 HighN/A0%Oct 16, 2025
CVE-2025-11683: Improper Restriction of Operations within the Bounds of a Memory Buffer6.5 MediumN/A0%Oct 16, 2025
CVE-2025-62375: Improper Certificate ValidationN/A6.9 Medium0%Oct 15, 2025
CVE-2025-43313: Improper Access Control5.5 MediumN/A0%Oct 15, 2025
CVE-2025-43282: Double Free5.5 MediumN/A0%Oct 15, 2025
CVE-2025-43281: Improper Authentication7.8 HighN/A0%Oct 15, 2025
CVE-2025-11619: Improper Certificate Validation8.8 HighN/A0%Oct 15, 2025
CVE-2025-11568: Improper Validation of Specified Quantity in Input4.4 MediumN/A0%Oct 15, 2025
CVE-2025-43280: Improper Verification of Source of a Communication ChannelN/AN/A0%Oct 15, 2025
CVE-2025-11832: Allocation of Resources Without Limits or Throttling9.8 Critical10.0 Critical0%Oct 15, 2025
CVE-2025-62410: Improperly Controlled Modification of Object Prototype AttributesN/A9.4 Critical0%Oct 15, 2025
CVE-2025-62382: External Control of File Name or Path7.7 HighN/A0%Oct 15, 2025
CVE-2025-62381: Improperly Controlled Modification of Object Prototype AttributesN/A8.3 High1%Oct 15, 2025
CVE-2025-62371: Improper Certificate Validation7.4 HighN/A0%Oct 15, 2025
CVE-2025-62380: Improper Neutralization of Input During Web Page GenerationN/A2.9 Low0%Oct 15, 2025
CVE-2025-62378: Use of Incorrectly-Resolved Name or Reference6.1 MediumN/A0%Oct 15, 2025
CVE-2025-58133: Authentication Bypass Using an Alternate Path or Channel5.3 MediumN/A0%Oct 15, 2025
CVE-2025-58132: Improper Neutralization of Special Elements used in a Command4.1 MediumN/A2%Oct 15, 2025
84151-84175 of 677876