The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-20351: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 15, 2025
CVE-2025-20350: Stack-based Buffer Overflow7.5 HighN/A0%Oct 15, 2025
CVE-2025-20329: Insertion of Sensitive Information into Log File4.9 MediumN/A0%Oct 15, 2025
CVE-2025-10577: Incorrect Privilege AssignmentN/A8.5 High0%Oct 15, 2025
CVE-2025-10576: Incorrect Privilege AssignmentN/A8.5 High0%Oct 15, 2025
CVE-2025-62379: URL Redirection to Untrusted Site3.1 LowN/A0%Oct 15, 2025
CVE-2025-62370: Uncaught Exception7.5 HighN/A0%Oct 15, 2025
CVE-2025-61990: Double Free7.5 High8.7 High0%Oct 15, 2025
CVE-2025-61935: Unchecked Return Value7.5 High8.7 High0%Oct 15, 2025
CVE-2025-61933: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Oct 15, 2025
CVE-2025-59419: Improper Neutralization of CRLF SequencesN/A5.5 Medium2%Oct 15, 2025
CVE-2025-58071: Use of Uninitialized Variable7.5 High8.7 High0%Oct 15, 2025
CVE-2025-57780: Execution with Unnecessary Privileges8.8 High8.5 High0%Oct 15, 2025
CVE-2025-53860: Invocation of Process Using Visible Sensitive Information4.1 Medium5.6 Medium0%Oct 15, 2025
CVE-2025-2529: Improper Handling of Syntactically Invalid Structure2.9 LowN/A0%Oct 15, 2025
CVE-2025-9548: NULL Pointer Dereference5.5 Medium6.8 Medium0%Oct 15, 2025
CVE-2025-8486: Execution with Unnecessary Privileges7.8 High8.5 High0%Oct 15, 2025
CVE-2025-6026: Improper Certificate Validation3.1 Low2.3 Low0%Oct 15, 2025
CVE-2025-56749: Use of Hard-coded Credentials9.4 CriticalN/A0%Oct 15, 2025
CVE-2025-56748: Weak Password Recovery Mechanism for Forgotten Password6.4 MediumN/A0%Oct 15, 2025
CVE-2025-55083: Buffer Over-read5.3 Medium6.9 Medium0%Oct 15, 2025
CVE-2025-10699: Improper Certificate Validation5.3 Medium6.0 Medium0%Oct 15, 2025
CVE-2025-10581: Uncontrolled Search Path Element7.8 High8.5 High0%Oct 15, 2025
CVE-2025-61974: Missing Release of Memory after Effective Lifetime7.5 High8.7 High0%Oct 15, 2025
CVE-2025-61960: NULL Pointer Dereference7.5 High8.7 High0%Oct 15, 2025
84176-84200 of 677876