The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-62385: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A1%Oct 13, 2025
CVE-2025-62384: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A1%Oct 13, 2025
CVE-2025-62383: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A1%Oct 13, 2025
CVE-2025-62365: Improper Neutralization of Input During Web Page Generation6.1 Medium5.5 Medium0%Oct 13, 2025
CVE-2025-62363: Improper Link Resolution Before File Access7.8 HighN/A0%Oct 13, 2025
CVE-2025-62362: Exposure of Private Personal Information to an Unauthorized ActorN/A6.9 Medium0%Oct 13, 2025
CVE-2025-62361: URL Redirection to Untrusted Site6.1 Medium4.8 Medium0%Oct 13, 2025
CVE-2025-62360: Improper Neutralization of Special Elements used in an SQL Command8.8 High9.4 Critical1%Oct 13, 2025
CVE-2025-62359: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Oct 13, 2025
CVE-2025-62358: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Oct 13, 2025
CVE-2025-62251: Incorrect Permission Assignment for Critical Resource6.5 Medium4.8 Medium0%Oct 13, 2025
CVE-2025-62179: Improper Neutralization of Special Elements used in an SQL Command8.8 High8.6 High0%Oct 13, 2025
CVE-2025-62178: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Oct 13, 2025
CVE-2025-62177: Improper Neutralization of Special Elements used in an SQL Command8.8 High8.6 High1%Oct 13, 2025
CVE-2025-11623: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A1%Oct 13, 2025
CVE-2025-9713: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A15%Oct 13, 2025
CVE-2025-62364: Improper Link Resolution Before File Access6.2 MediumN/A1%Oct 13, 2025
CVE-2025-62252: Authorization Bypass Through User-Controlled Key4.3 Medium5.3 Medium0%Oct 13, 2025
CVE-2025-62246: Improper Neutralization of Input During Web Page Generation5.4 Medium4.8 Medium0%Oct 13, 2025
CVE-2025-62176: Improper Handling of Insufficient Permissions or Privileges4.3 MediumN/A0%Oct 13, 2025
CVE-2025-62175: Improper Check for Dropped Privileges4.3 MediumN/A0%Oct 13, 2025
CVE-2025-62174: Insufficient Session Expiration3.5 LowN/A0%Oct 13, 2025
CVE-2025-61688: Exposure of Sensitive Information to an Unauthorized Actor8.6 HighN/A0%Oct 13, 2025
CVE-2025-59836: Improper Check or Handling of Exceptional Conditions5.3 MediumN/A1%Oct 13, 2025
CVE-2025-11622: Deserialization of Untrusted Data7.8 HighN/A1%Oct 13, 2025
84651-84675 of 390695