The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-11380: Missing Authorization5.9 MediumN/A0%Oct 11, 2025
CVE-2025-54654: Undefined Security Weakness6.2 MediumN/A0%Oct 11, 2025
CVE-2025-31718: Undefined Security Weakness7.5 HighN/A0%Oct 11, 2025
CVE-2025-31717: Undefined Security Weakness7.5 HighN/A0%Oct 11, 2025
CVE-2025-11590: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 11, 2025
CVE-2025-9554: Undefined Security Weakness5.3 MediumN/A0%Oct 10, 2025
CVE-2025-9553: Undefined Security Weakness5.3 MediumN/A0%Oct 10, 2025
CVE-2025-9552: Undefined Security Weakness5.3 MediumN/A0%Oct 10, 2025
CVE-2025-9551: Improper Restriction of Excessive Authentication Attempts6.5 MediumN/A0%Oct 10, 2025
CVE-2025-9550: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 10, 2025
CVE-2025-9549: Missing Authorization6.5 MediumN/A0%Oct 10, 2025
CVE-2025-8093: Authentication Bypass Using an Alternate Path or Channel8.8 HighN/A0%Oct 10, 2025
CVE-2025-62162: Improper Input Validation7.5 HighN/A0%Oct 10, 2025
CVE-2025-62159: Improper Access ControlN/A8.7 High0%Oct 10, 2025
CVE-2025-52885: Use After FreeN/A6.1 Medium0%Oct 10, 2025
CVE-2025-52647: Improper Neutralization of HTTP Headers for Scripting Syntax6.1 MediumN/A0%Oct 10, 2025
CVE-2025-11626: Loop with Unreachable Exit Condition5.5 MediumN/A0%Oct 10, 2025
CVE-2025-61912: Improper Encoding or Escaping of Output5.3 Medium5.5 Medium0%Oct 10, 2025
CVE-2025-61911: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)6.5 Medium5.5 Medium0%Oct 10, 2025
CVE-2025-11589: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 10, 2025
CVE-2025-11588: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 10, 2025
CVE-2025-11586: Stack-based Buffer Overflow8.8 High7.4 High0%Oct 10, 2025
CVE-2025-11585: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 10, 2025
CVE-2025-11584: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 10, 2025
CVE-2025-62245: Cross-Site Request Forgery (CSRF)4.3 Medium5.1 Medium0%Oct 10, 2025
84826-84850 of 574060