The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-59218: Improper Access Control9.6 CriticalN/A0%Oct 9, 2025
CVE-2025-55321: Improper Neutralization of Input During Web Page Generation9.3 CriticalN/A0%Oct 9, 2025
CVE-2025-43296: Cross-Site Request Forgery (CSRF)5.5 MediumN/A0%Oct 9, 2025
CVE-2025-35062: Incorrect Default Permissions5.3 Medium6.9 Medium0%Oct 9, 2025
CVE-2025-35061: Authentication Bypass by Capture-replay5.9 Medium8.2 High0%Oct 9, 2025
CVE-2025-35060: Improper Neutralization of Input During Web Page Generation5.5 Medium5.1 Medium0%Oct 9, 2025
CVE-2025-35059: URL Redirection to Untrusted Site4.3 Medium5.3 Medium0%Oct 9, 2025
CVE-2025-35058: Authentication Bypass by Capture-replay5.9 Medium8.2 High0%Oct 9, 2025
CVE-2025-35057: Authentication Bypass by Capture-replay5.3 Medium6.0 Medium0%Oct 9, 2025
CVE-2025-35056: Improper Limitation of a Pathname to a Restricted Directory5.0 Medium5.3 Medium0%Oct 9, 2025
CVE-2025-35055: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High0%Oct 9, 2025
CVE-2025-35054: Insecure Storage of Sensitive Information5.3 Medium4.8 Medium0%Oct 9, 2025
CVE-2025-35053: Improper Limitation of a Pathname to a Restricted Directory6.4 Medium6.1 Medium0%Oct 9, 2025
CVE-2025-35052: Use of Hard-coded Cryptographic Key5.3 Medium6.3 Medium0%Oct 9, 2025
CVE-2025-35051: Deserialization of Untrusted Data9.8 Critical9.2 Critical0%Oct 9, 2025
CVE-2025-35050: Deserialization of Untrusted Data9.8 Critical9.3 Critical0%Oct 9, 2025
CVE-2025-11558: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 9, 2025
CVE-2025-11557: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 9, 2025
CVE-2025-11556: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 9, 2025
CVE-2025-11555: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 9, 2025
CVE-2016-15047: Improper Neutralization of Special Elements used in an OS CommandN/A8.7 High0%Oct 9, 2025
CVE-2025-34248: Improper Limitation of a Pathname to a Restricted DirectoryN/A7.2 High0%Oct 9, 2025
CVE-2025-60316: Improper Neutralization of Special Elements used in an SQL Command9.4 CriticalN/A0%Oct 9, 2025
CVE-2025-11554: Insecure Inherited Permissions6.3 Medium2.1 Low0%Oct 9, 2025
CVE-2025-11553: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 9, 2025
84951-84975 of 399626