The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-21047: Undefined Security Weakness5.2 MediumN/A0%Oct 10, 2025
CVE-2025-21046: Undefined Security Weakness2.4 LowN/A0%Oct 10, 2025
CVE-2025-21045: Undefined Security Weakness4.0 MediumN/A0%Oct 10, 2025
CVE-2025-21044: Out-of-bounds Write5.7 MediumN/A0%Oct 10, 2025
CVE-2025-10124: Undefined Security Weakness4.5 MediumN/A0%Oct 10, 2025
CVE-2025-61871: Unquoted Search Path or Element6.7 Medium8.4 High0%Oct 10, 2025
CVE-2025-11570: Improper Neutralization of Input During Web Page Generation4.6 Medium1.9 Low0%Oct 10, 2025
CVE-2025-11569: Undefined Security WeaknessN/AN/A0%Oct 10, 2025
CVE-2025-11450: Improper Neutralization of Input During Web Page GenerationN/A5.3 Medium0%Oct 10, 2025
CVE-2025-11449: Improper Neutralization of Input During Web Page GenerationN/A5.3 Medium0%Oct 10, 2025
CVE-2025-61928: Improper AuthorizationN/A9.3 Critical0%Oct 9, 2025
CVE-2025-61926: Insecure Default Variable InitializationN/A4.6 Medium0%Oct 9, 2025
CVE-2025-62240: Improper Neutralization of Input During Web Page Generation5.4 Medium4.8 Medium0%Oct 9, 2025
CVE-2025-61783: Incorrect Implementation of Authentication AlgorithmN/A6.3 Medium0%Oct 9, 2025
CVE-2025-61779: Authorization Bypass Through User-Controlled KeyN/A8.7 High0%Oct 9, 2025
CVE-2025-61773: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.1 HighN/A0%Oct 9, 2025
CVE-2025-61602: Improper Check or Handling of Exceptional Conditions7.5 HighN/A0%Oct 9, 2025
CVE-2025-61601: Improper Check or Handling of Exceptional Conditions7.5 HighN/A0%Oct 9, 2025
CVE-2025-60375: Authentication Bypass by Alternate Name7.3 HighN/A0%Oct 9, 2025
CVE-2025-59286: Improper Neutralization of Special Elements used in a Command9.3 CriticalN/A0%Oct 9, 2025
CVE-2025-59272: Improper Neutralization of Special Elements used in a Command9.3 CriticalN/A0%Oct 9, 2025
CVE-2025-59271: Improper Authorization8.7 HighN/A0%Oct 9, 2025
CVE-2025-59252: Improper Neutralization of Special Elements used in a Command9.3 CriticalN/A0%Oct 9, 2025
CVE-2025-59247: Improper Privilege Management8.8 HighN/A0%Oct 9, 2025
CVE-2025-59246: Missing Authentication for Critical Function9.8 CriticalN/A0%Oct 9, 2025
84926-84950 of 398978