The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-47150: Missing Release of Memory after Effective Lifetime6.5 Medium7.1 High0%Oct 15, 2025
CVE-2025-47148: Improper Resource Shutdown or Release6.5 Medium7.1 High0%Oct 15, 2025
CVE-2025-46706: Allocation of Resources Without Limits or Throttling7.5 High8.7 High0%Oct 15, 2025
CVE-2025-41430: Allocation of Resources Without Limits or Throttling7.5 High8.7 High0%Oct 15, 2025
CVE-2025-9640: Use of Uninitialized Resource4.3 MediumN/A0%Oct 15, 2025
CVE-2025-10869: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Oct 15, 2025
CVE-2025-55082: Out-of-bounds Read5.3 Medium6.9 Medium0%Oct 15, 2025
CVE-2025-55081: Buffer Over-read9.1 Critical6.9 Medium0%Oct 15, 2025
CVE-2025-9967: Authentication Bypass Using an Alternate Path or Channel9.8 CriticalN/A0%Oct 15, 2025
CVE-2025-11728: Missing Authentication for Critical Function5.3 MediumN/A0%Oct 15, 2025
CVE-2025-11722: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A1%Oct 15, 2025
CVE-2025-11701: Missing Authorization5.3 MediumN/A0%Oct 15, 2025
CVE-2025-11692: Missing Authorization5.3 MediumN/A0%Oct 15, 2025
CVE-2025-11365: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Oct 15, 2025
CVE-2025-11196: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Oct 15, 2025
CVE-2025-11177: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Oct 15, 2025
CVE-2025-10754: Unrestricted Upload of File with Dangerous Type7.2 HighN/A1%Oct 15, 2025
CVE-2025-10743: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Oct 15, 2025
CVE-2025-10730: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Oct 15, 2025
CVE-2025-10682: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Oct 15, 2025
CVE-2025-10660: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Oct 15, 2025
CVE-2025-10648: Missing Authorization5.3 MediumN/A0%Oct 15, 2025
CVE-2025-10575: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Oct 15, 2025
CVE-2025-10486: Insertion of Sensitive Information into Log File5.3 MediumN/A0%Oct 15, 2025
CVE-2025-10313: Missing Authorization7.2 HighN/A0%Oct 15, 2025
84226-84250 of 677876