The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-58681: Missing Authorization5.3 MediumN/A0%Sep 22, 2025
CVE-2025-58683: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 22, 2025
CVE-2025-58684: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 22, 2025
CVE-2025-58685: Missing Authorization5.3 MediumN/A0%Sep 22, 2025
CVE-2025-58686: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Sep 22, 2025
CVE-2025-58687: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 22, 2025
CVE-2025-58688: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 22, 2025
CVE-2025-58689: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 22, 2025
CVE-2025-58691: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 22, 2025
CVE-2025-58690: Cross-Site Request Forgery (CSRF)7.1 HighN/A0%Sep 22, 2025
CVE-2025-58702: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 22, 2025
CVE-2025-58704: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Sep 22, 2025
CVE-2025-59420: Insufficient Verification of Data Authenticity7.5 HighN/A0%Sep 22, 2025
CVE-2025-59418: Allocation of Resources Without Limits or Throttling5.5 MediumN/A0%Sep 22, 2025
CVE-2025-57441: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A1%Sep 22, 2025
CVE-2025-57440: Uncontrolled Resource Consumption7.5 HighN/A0%Sep 22, 2025
CVE-2025-57439: Improper Control of Generation of Code8.8 HighN/A1%Sep 22, 2025
CVE-2025-57438: Improper Access Control6.8 MediumN/A0%Sep 22, 2025
CVE-2025-57437: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A1%Sep 22, 2025
CVE-2025-55888: Improper Neutralization of Input During Web Page Generation7.3 HighN/A0%Sep 22, 2025
CVE-2025-55886: Protection Mechanism Failure6.5 MediumN/A0%Sep 22, 2025
CVE-2025-55885: Improper Neutralization of Special Elements used in an SQL Command6.3 MediumN/A0%Sep 22, 2025
CVE-2025-43953: Improper Neutralization of Special Elements used in a Command8.8 HighN/A8%Sep 22, 2025
CVE-2025-10809: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 22, 2025
CVE-2025-10808: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2025
86051-86075 of 552652