The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-60027: Undefined Security WeaknessN/AN/AN/ASep 26, 2025
CVE-2025-60026: Undefined Security WeaknessN/AN/AN/ASep 26, 2025
CVE-2025-10999: NULL Pointer Dereference3.3 Low1.9 Low0%Sep 26, 2025
CVE-2025-10998: NULL Pointer Dereference3.3 Low1.9 Low0%Sep 26, 2025
CVE-2025-10997: Heap-based Buffer Overflow5.3 Medium1.9 Low0%Sep 26, 2025
CVE-2025-10996: Heap-based Buffer Overflow5.3 Medium1.9 Low0%Sep 26, 2025
CVE-2025-8906: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 26, 2025
CVE-2025-8200: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 26, 2025
CVE-2025-10995: Improper Restriction of Operations within the Bounds of a Memory Buffer5.3 Medium1.9 Low0%Sep 26, 2025
CVE-2025-10994: Use After Free5.3 Medium1.9 Low0%Sep 26, 2025
CVE-2025-10993: Improper Control of Generation of Code4.7 Medium5.1 Medium0%Sep 26, 2025
CVE-2025-10992: Improper Authorization5.3 Medium5.5 Medium0%Sep 26, 2025
CVE-2025-10752: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Sep 26, 2025
CVE-2025-10178: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 26, 2025
CVE-2025-60251: Missing Authentication for Critical Function5.0 MediumN/A0%Sep 26, 2025
CVE-2025-60250: Use of Hard-coded Cryptographic Key4.7 MediumN/A0%Sep 26, 2025
CVE-2025-60017: Improper Neutralization of Special Elements used in an OS Command8.2 HighN/A1%Sep 26, 2025
CVE-2025-10989: Improper Authorization6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-10988: Improper Authorization6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-10987: Improper Authorization6.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-10981: Improper Authorization4.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-10980: Improper Authorization4.3 Medium2.1 Low0%Sep 26, 2025
CVE-2025-56769: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A0%Sep 25, 2025
CVE-2025-10979: Improper Authorization4.3 Medium2.1 Low0%Sep 25, 2025
CVE-2025-10978: Improper Authorization4.3 Medium2.1 Low0%Sep 25, 2025
85776-85800 of 682148