The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-52614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute3.5 LowN/A0%Oct 12, 2025
CVE-2025-31969: Improperly Implemented Security Check for Standard4.0 MediumN/A0%Oct 12, 2025
CVE-2025-11631: Improper Limitation of a Pathname to a Restricted Directory5.4 Medium2.1 Low0%Oct 12, 2025
CVE-2025-11630: Improper Limitation of a Pathname to a Restricted Directory6.3 Medium2.1 Low0%Oct 12, 2025
CVE-2025-11629: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 12, 2025
CVE-2025-31992: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)4.6 MediumN/A0%Oct 12, 2025
CVE-2025-52616: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Oct 12, 2025
CVE-2025-11628: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Oct 12, 2025
CVE-2025-61884: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A98%Oct 12, 2025
CVE-2025-31998: Improper Check or Handling of Exceptional Conditions3.5 LowN/A0%Oct 12, 2025
CVE-2025-31997: Authorization Bypass Through User-Controlled Key4.2 MediumN/A0%Oct 12, 2025
CVE-2025-31993: Server-Side Request Forgery (SSRF)3.5 LowN/A0%Oct 12, 2025
CVE-2025-11615: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 11, 2025
CVE-2025-11614: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 11, 2025
CVE-2025-11613: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-11612: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-11611: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-11610: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-11609: Use of Hard-coded Cryptographic Key3.7 Low2.9 Low0%Oct 11, 2025
CVE-2025-11608: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 11, 2025
CVE-2025-11607: Improper Limitation of a Pathname to a Restricted Directory6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-11606: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-11605: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-11604: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 11, 2025
CVE-2025-11603: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
84751-84775 of 404943