The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-11491: Improper Neutralization of Special Elements used in an OS Command6.3 Medium2.1 Low0%Oct 8, 2025
CVE-2025-11490: Improper Neutralization of Special Elements used in an OS Command6.3 Medium2.1 Low0%Oct 8, 2025
CVE-2025-9868: Server-Side Request Forgery (SSRF)N/A8.7 High0%Oct 8, 2025
CVE-2025-61906: Exposure of Sensitive Information to an Unauthorized Actor4.3 Medium2.3 Low0%Oct 8, 2025
CVE-2025-61788: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Oct 8, 2025
CVE-2025-42706: Origin Validation Error6.5 MediumN/A0%Oct 8, 2025
CVE-2025-42701: Time-of-check Time-of-use (TOCTOU) Race Condition5.6 MediumN/A0%Oct 8, 2025
CVE-2025-11489: UNIX Symbolic Link (Symlink) Following4.5 Medium1.1 Low0%Oct 8, 2025
CVE-2025-11488: Improper Neutralization of Special Elements used in a Command7.3 High5.5 Medium2%Oct 8, 2025
CVE-2025-11487: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 8, 2025
CVE-2025-9970: Cleartext Storage of Sensitive Information in Memory7.4 High5.7 Medium0%Oct 8, 2025
CVE-2025-53967: Unprotected Alternate Channel8.0 HighN/A0%Oct 8, 2025
CVE-2025-11486: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 8, 2025
CVE-2025-11485: Improper Neutralization of Input During Web Page Generation2.4 Low1.9 Low0%Oct 8, 2025
CVE-2025-11481: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Oct 8, 2025
CVE-2025-60318: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 8, 2025
CVE-2025-5009: Exposure of Private Personal Information to an Unauthorized ActorN/A1.0 Low0%Oct 8, 2025
CVE-2025-59303: Incomplete Filtering of Special Elements6.4 MediumN/A0%Oct 8, 2025
CVE-2025-36636: Improper Access Control4.3 MediumN/A0%Oct 8, 2025
CVE-2025-61672: Improper Validation of Specified Type of InputN/A5.3 Medium0%Oct 8, 2025
CVE-2025-60834: Deserialization of Untrusted Data6.5 MediumN/A0%Oct 8, 2025
CVE-2025-60313: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 8, 2025
CVE-2025-43771: Improper Neutralization of Input During Web Page Generation5.4 Medium4.8 Medium0%Oct 8, 2025
CVE-2025-43724: Authorization Bypass Through User-Controlled Key4.4 MediumN/A0%Oct 8, 2025
CVE-2025-11480: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 8, 2025
85076-85100 of 400966