The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-46148: Undefined Security Weakness5.3 MediumN/A0%Sep 25, 2025
CVE-2025-40838: Insufficiently Protected Credentials7.5 High5.1 Medium0%Sep 25, 2025
CVE-2025-40837: Missing Authorization8.8 High8.7 High0%Sep 25, 2025
CVE-2025-40836: Improper Input Validation9.8 Critical8.7 High0%Sep 25, 2025
CVE-2025-36857: Incorrect Default Permissions3.3 LowN/A0%Sep 25, 2025
CVE-2025-36601: Exposure of Sensitive Information to an Unauthorized Actor4.0 MediumN/A0%Sep 25, 2025
CVE-2025-27262: Improper Neutralization of Special Elements used in an OS Command7.8 High8.5 High1%Sep 25, 2025
CVE-2025-10951: Improper Limitation of a Pathname to a Restricted Directory7.3 High5.5 Medium1%Sep 25, 2025
CVE-2025-10950: Deserialization of Untrusted Data6.3 Medium2.1 Low0%Sep 25, 2025
CVE-2025-10949: Improper Neutralization of Input During Web Page Generation2.4 Low1.9 Low0%Sep 25, 2025
CVE-2025-10542: Use of Default Credentials9.8 CriticalN/A1%Sep 25, 2025
CVE-2025-10541: Incorrect Permission Assignment for Critical Resource7.8 HighN/A0%Sep 25, 2025
CVE-2020-36851: Permissive Cross-domain Policy with Untrusted DomainsN/A9.5 Critical1%Sep 25, 2025
CVE-2025-5494: Improper Privilege Management3.9 LowN/A0%Sep 25, 2025
CVE-2025-59839: Improper Neutralization of Input During Web Page Generation8.6 HighN/A0%Sep 25, 2025
CVE-2025-59834: Improper Neutralization of Special Elements used in a Command9.8 CriticalN/A2%Sep 25, 2025
CVE-2025-59831: Improper Neutralization of Special Elements used in a Command8.8 High8.7 High2%Sep 25, 2025
CVE-2025-59426: URL Redirection to Untrusted Site4.3 MediumN/A0%Sep 25, 2025
CVE-2025-59422: Improper Access Control3.1 Low6.0 Medium0%Sep 25, 2025
CVE-2025-57317: Uncontrolled Resource Consumption7.5 HighN/A0%Sep 25, 2025
CVE-2025-27261: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical8.7 High0%Sep 25, 2025
CVE-2025-26278: Improperly Controlled Modification of Object Prototype Attributes7.5 HighN/A0%Sep 25, 2025
CVE-2025-10948: Buffer Copy without Checking Size of Input8.8 High7.4 High1%Sep 25, 2025
CVE-2025-10540: Cleartext Transmission of Sensitive Information6.5 MediumN/A0%Sep 25, 2025
CVE-2025-10467: Improper Neutralization of Input During Web Page Generation8.9 HighN/A0%Sep 25, 2025
85826-85850 of 682148