The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-20313: Path Traversal: '.../...//'6.7 MediumN/A0%Sep 24, 2025
CVE-2025-20312: Loop with Unreachable Exit Condition7.7 HighN/A0%Sep 24, 2025
CVE-2025-20311: Undefined Security Weakness7.4 HighN/A0%Sep 24, 2025
CVE-2025-20293: Incomplete Cleanup5.3 MediumN/A0%Sep 24, 2025
CVE-2025-20240: Incomplete Denylist to Cross-Site Scripting6.1 MediumN/A0%Sep 24, 2025
CVE-2025-20160: Improper Authentication8.1 HighN/A0%Sep 24, 2025
CVE-2025-20149: Buffer Copy without Checking Size of Input6.5 MediumN/A0%Sep 24, 2025
CVE-2025-56816: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A1%Sep 24, 2025
CVE-2025-56815: Improper Limitation of a Pathname to a Restricted Directory7.1 HighN/A1%Sep 24, 2025
CVE-2025-20365: Improper Verification of Source of a Communication Channel4.3 MediumN/A0%Sep 24, 2025
CVE-2025-20364: Origin Validation Error4.3 MediumN/A0%Sep 24, 2025
CVE-2025-20339: Improper Access Control5.8 MediumN/A0%Sep 24, 2025
CVE-2025-20334: Improper Neutralization of Special Elements used in a Command8.8 HighN/A1%Sep 24, 2025
CVE-2025-10909: Improper Neutralization of Input During Web Page Generation2.4 Low1.9 Low0%Sep 24, 2025
CVE-2025-10892: External Control of Assumed-Immutable Web Parameter8.8 HighN/A0%Sep 24, 2025
CVE-2025-10891: External Control of Assumed-Immutable Web Parameter8.8 HighN/A7%Sep 24, 2025
CVE-2025-10890: Improper Protection of Physical Side Channels9.1 CriticalN/A0%Sep 24, 2025
CVE-2025-10585: Access of Resource Using Incompatible Type9.8 CriticalN/A5%Sep 24, 2025
CVE-2025-10502: Heap-based Buffer Overflow8.8 HighN/A0%Sep 24, 2025
CVE-2025-10501: Use After Free8.8 HighN/A0%Sep 24, 2025
CVE-2025-10500: Use After Free8.8 HighN/A0%Sep 24, 2025
CVE-2025-56819: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A3%Sep 24, 2025
CVE-2025-47329: Release of Invalid Pointer or Reference7.8 HighN/A0%Sep 24, 2025
CVE-2025-47328: Buffer Over-read7.5 HighN/A0%Sep 24, 2025
CVE-2025-47327: Use After Free7.8 HighN/A0%Sep 24, 2025
85876-85900 of 552652