The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-10735: Server-Side Request Forgery (SSRF)4.0 MediumN/A0%Oct 1, 2025
CVE-2025-10538: Authentication Bypass Using an Alternate Path or ChannelN/A8.8 High0%Oct 1, 2025
CVE-2025-61722: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61721: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61720: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61719: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61718: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61717: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61716: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61715: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61714: Undefined Security WeaknessN/AN/AN/AOct 1, 2025
CVE-2025-61792: Concurrent Execution using Shared Resource with Improper Synchronization6.4 MediumN/A0%Sep 30, 2025
CVE-2025-55191: Concurrent Execution using Shared Resource with Improper Synchronization6.5 MediumN/A0%Sep 30, 2025
CVE-2025-43826: Improper Neutralization of Input During Web Page Generation5.4 Medium4.8 Medium0%Sep 30, 2025
CVE-2025-24525: Use of Hard-coded Cryptographic Key7.5 High8.7 High0%Sep 30, 2025
CVE-2022-40285: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-56392: Authorization Bypass Through User-Controlled Key8.1 HighN/A0%Sep 30, 2025
CVE-2025-36262: Improper Validation of Syntactic Correctness of Input4.9 MediumN/A0%Sep 30, 2025
CVE-2025-36132: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 30, 2025
CVE-2025-10659: Improper Neutralization of Special Elements used in an OS Command9.8 Critical9.3 Critical1%Sep 30, 2025
CVE-2024-55017: URL Redirection to Untrusted Site7.5 HighN/A0%Sep 30, 2025
CVE-2025-56132: Authentication Bypass by Primary Weakness7.3 HighN/A8%Sep 30, 2025
CVE-2025-43827: Authorization Bypass Through User-Controlled Key4.3 Medium5.3 Medium0%Sep 30, 2025
CVE-2025-57254: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Sep 30, 2025
CVE-2025-56675: Incorrect Resource Transfer Between Spheres3.5 LowN/A0%Sep 30, 2025
85326-85350 of 566702