The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-61930: Cross-Site Request Forgery (CSRF)8.1 HighN/A0%Oct 10, 2025
CVE-2025-61929: Improper Control of Generation of Code9.6 CriticalN/A0%Oct 10, 2025
CVE-2025-61927: Improper Control of Generation of CodeN/A7.2 High1%Oct 10, 2025
CVE-2025-61925: Use of Externally-Controlled Input to Select Classes or Code6.5 MediumN/A0%Oct 10, 2025
CVE-2025-61921: Inefficient Regular Expression Complexity7.5 High2.7 Low0%Oct 10, 2025
CVE-2025-61920: Improper Input Validation7.5 HighN/A1%Oct 10, 2025
CVE-2025-61919: Uncontrolled Resource Consumption7.5 HighN/A0%Oct 10, 2025
CVE-2025-55903: Improper Encoding or Escaping of Output8.3 HighN/A0%Oct 10, 2025
CVE-2025-11583: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 10, 2025
CVE-2025-11582: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 10, 2025
CVE-2025-61505: Deserialization of Untrusted Data6.5 MediumN/A0%Oct 10, 2025
CVE-2025-60880: Improper Neutralization of Input During Web Page Generation8.3 HighN/A0%Oct 10, 2025
CVE-2025-11581: Missing Authorization5.3 Medium5.5 Medium0%Oct 10, 2025
CVE-2025-60838: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A0%Oct 10, 2025
CVE-2025-60268: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A0%Oct 10, 2025
CVE-2025-23309: Uncontrolled Search Path Element8.2 HighN/A0%Oct 10, 2025
CVE-2025-23282: Double Free7.0 HighN/A0%Oct 10, 2025
CVE-2025-23280: Use After Free7.0 HighN/A0%Oct 10, 2025
CVE-2025-11618: NULL Pointer Dereference4.3 Medium5.3 Medium0%Oct 10, 2025
CVE-2025-11617: Buffer Over-read5.4 Medium5.3 Medium0%Oct 10, 2025
CVE-2025-11616: Buffer Over-read5.4 Medium5.3 Medium0%Oct 10, 2025
CVE-2025-11580: Missing Authorization5.3 Medium5.5 Medium2%Oct 10, 2025
CVE-2025-61780: Exposure of Sensitive Information to an Unauthorized Actor5.8 MediumN/A0%Oct 10, 2025
CVE-2025-61689: Improper Neutralization of CRLF Sequences in HTTP HeadersN/A8.7 High0%Oct 10, 2025
CVE-2025-60308: Improper Neutralization of Input During Web Page Generation4.1 MediumN/A0%Oct 10, 2025
84851-84875 of 403401