The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-10558: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Oct 13, 2025
CVE-2025-10557: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Oct 13, 2025
CVE-2025-10556: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Oct 13, 2025
CVE-2025-10552: Improper Neutralization of Input During Web Page Generation8.7 HighN/A0%Oct 13, 2025
CVE-2025-9265: Origin Validation ErrorN/A10.0 Critical0%Oct 13, 2025
CVE-2025-8915: Exposure of Sensitive Information to an Unauthorized ActorN/A8.7 High0%Oct 13, 2025
CVE-2025-27259: Improper Neutralization of Input During Web Page Generation5.4 Medium2.4 Low0%Oct 13, 2025
CVE-2025-27258: Improper Access Control9.8 Critical6.9 Medium0%Oct 13, 2025
CVE-2025-11666: Use of Hard-coded Password6.7 Medium7.0 High0%Oct 13, 2025
CVE-2025-11665: Improper Neutralization of Special Elements used in an OS Command4.7 Medium5.1 Medium7%Oct 13, 2025
CVE-2025-11664: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Oct 13, 2025
CVE-2025-0636: Improper Neutralization of Special Elements used in an OS Command8.4 HighN/A0%Oct 13, 2025
CVE-2025-9698: Undefined Security Weakness6.8 MediumN/A0%Oct 13, 2025
CVE-2025-11663: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Oct 13, 2025
CVE-2025-31995: Improper Input Validation3.5 LowN/A1%Oct 13, 2025
CVE-2025-11662: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 13, 2025
CVE-2025-11661: Missing Authentication for Critical Function7.3 High5.5 Medium1%Oct 13, 2025
CVE-2025-31996: Files or Directories Accessible to External Parties5.3 MediumN/A0%Oct 13, 2025
CVE-2025-31994: Improper Neutralization of Input During Web Page Generation4.3 MediumN/A0%Oct 13, 2025
CVE-2025-11660: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium0%Oct 13, 2025
CVE-2025-11659: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium1%Oct 13, 2025
CVE-2025-11658: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium0%Oct 13, 2025
CVE-2025-11657: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium1%Oct 13, 2025
CVE-2025-11656: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium1%Oct 13, 2025
CVE-2025-11655: Unrestricted Upload of File with Dangerous Type4.7 Medium2.0 Low0%Oct 13, 2025
84701-84725 of 397021