The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-8430: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Oct 14, 2025
CVE-2025-60535: Cross-Site Request Forgery (CSRF)7.3 HighN/A0%Oct 14, 2025
CVE-2025-59502: Uncontrolled Resource Consumption7.5 HighN/A1%Oct 14, 2025
CVE-2025-59497: Time-of-check Time-of-use (TOCTOU) Race Condition7.0 HighN/A0%Oct 14, 2025
CVE-2025-59494: Improper Access Control7.8 HighN/A1%Oct 14, 2025
CVE-2025-59295: Heap-based Buffer Overflow8.8 HighN/A2%Oct 14, 2025
CVE-2025-59294: Exposure of Sensitive Information to an Unauthorized Actor2.1 LowN/A1%Oct 14, 2025
CVE-2025-59292: External Control of File Name or Path8.2 HighN/A0%Oct 14, 2025
CVE-2025-59291: External Control of File Name or Path8.2 HighN/A0%Oct 14, 2025
CVE-2025-59290: Use After Free7.8 HighN/A0%Oct 14, 2025
CVE-2025-59289: Double Free7.0 HighN/A0%Oct 14, 2025
CVE-2025-59288: Improper Verification of Cryptographic Signature5.3 MediumN/A0%Oct 14, 2025
CVE-2025-59287: Deserialization of Untrusted Data9.8 CriticalN/A100%Oct 14, 2025
CVE-2025-59285: Deserialization of Untrusted Data7.0 HighN/A1%Oct 14, 2025
CVE-2025-59284: Exposure of Sensitive Information to an Unauthorized Actor3.3 LowN/A1%Oct 14, 2025
CVE-2025-59282: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A1%Oct 14, 2025
CVE-2025-59281: Improper Link Resolution Before File Access7.8 HighN/A0%Oct 14, 2025
CVE-2025-59280: Improper Authentication3.1 LowN/A0%Oct 14, 2025
CVE-2025-59278: Improper Validation of Specified Type of Input7.8 HighN/A0%Oct 14, 2025
CVE-2025-59277: Improper Validation of Specified Type of Input7.8 HighN/A0%Oct 14, 2025
CVE-2025-59275: Improper Validation of Specified Type of Input7.8 HighN/A0%Oct 14, 2025
CVE-2025-59261: Time-of-check Time-of-use (TOCTOU) Race Condition7.0 HighN/A0%Oct 14, 2025
CVE-2025-59260: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Oct 14, 2025
CVE-2025-59259: Improper Validation of Specified Type of Input6.5 MediumN/A2%Oct 14, 2025
CVE-2025-59258: Insertion of Sensitive Information into Log File6.2 MediumN/A1%Oct 14, 2025
84376-84400 of 677876