The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-8121: Improper Neutralization of Special Elements used in an SQL Command8.8 High8.7 High0%Sep 30, 2025
CVE-2025-8120: Unrestricted Upload of File with Dangerous Type9.8 Critical10.0 Critical0%Sep 30, 2025
CVE-2025-8119: Cross-Site Request Forgery (CSRF)4.3 Medium5.1 Medium0%Sep 30, 2025
CVE-2025-8118: Improper Restriction of Excessive Authentication Attempts6.5 Medium6.9 Medium0%Sep 30, 2025
CVE-2025-8117: Missing Initialization of Resource7.5 High8.7 High0%Sep 30, 2025
CVE-2025-8116: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Sep 30, 2025
CVE-2025-7065: Unrestricted Upload of File with Dangerous Type9.8 Critical10.0 Critical0%Sep 30, 2025
CVE-2025-7063: Unrestricted Upload of File with Dangerous Type9.8 Critical10.0 Critical0%Sep 30, 2025
CVE-2025-7052: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Sep 30, 2025
CVE-2025-7038: Authentication Bypass Using an Alternate Path or Channel8.2 HighN/A1%Sep 30, 2025
CVE-2025-6941: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 30, 2025
CVE-2025-6815: Improper Neutralization of Input During Web Page Generation5.5 MediumN/A0%Sep 30, 2025
CVE-2025-61633: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61632: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61631: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61630: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61629: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61628: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61627: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61626: Undefined Security WeaknessN/AN/AN/ASep 30, 2025
CVE-2025-61584: Improper Neutralization of Special Elements used in a CommandN/A9.3 Critical0%Sep 30, 2025
CVE-2025-59956: Reliance on Reverse DNS Resolution for a Security-Critical Action6.5 MediumN/A0%Sep 30, 2025
CVE-2025-59954: Improper Control of Generation of Code9.8 Critical9.3 Critical0%Sep 30, 2025
CVE-2025-59668: NULL Pointer Dereference7.5 High8.7 High0%Sep 30, 2025
CVE-2025-41099: Authorization Bypass Through User-Controlled Key6.5 Medium7.1 High0%Sep 30, 2025
85401-85425 of 566702