The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-36239: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 27, 2025
CVE-2024-43192: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Sep 27, 2025
CVE-2025-59945: Incorrect Privilege Assignment8.1 HighN/A0%Sep 27, 2025
CVE-2025-59939: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Sep 27, 2025
CVE-2025-59938: Heap-based Buffer Overflow6.5 MediumN/A0%Sep 27, 2025
CVE-2025-59936: Improper Encoding or Escaping of Output9.4 CriticalN/A0%Sep 27, 2025
CVE-2025-59932: Improper Access Control8.6 HighN/A0%Sep 27, 2025
CVE-2025-36144: Insertion of Sensitive Information into Log File3.3 LowN/A0%Sep 27, 2025
CVE-2025-59934: Improper Verification of Cryptographic Signature9.4 CriticalN/A0%Sep 26, 2025
CVE-2025-59845: Origin Validation Error8.2 HighN/A0%Sep 26, 2025
CVE-2025-11048: Improper Authorization6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-11047: Improper Authorization6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-11046: Server-Side Request Forgery (SSRF)7.3 High5.5 Medium0%Sep 26, 2025
CVE-2025-11045: Improper Neutralization of Special Elements used in a Command7.3 High5.5 Medium1%Sep 26, 2025
CVE-2025-10657: Improper Privilege ManagementN/A8.7 High0%Sep 26, 2025
CVE-2025-57692: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Sep 26, 2025
CVE-2025-50879: Undefined Security WeaknessN/AN/AN/ASep 26, 2025
CVE-2025-11041: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-11040: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 26, 2025
CVE-2025-11039: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 26, 2025
CVE-2025-11038: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-11037: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 26, 2025
CVE-2025-11036: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 26, 2025
CVE-2025-11035: Improper Restriction of XML External Entity Reference6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-58384: Deserialization of Untrusted Data10.0 CriticalN/A1%Sep 26, 2025
85626-85650 of 391694