The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-59411: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 22, 2025
CVE-2025-59335: Insufficient Session Expiration7.1 HighN/A0%Sep 22, 2025
CVE-2025-57434: Improper Authentication8.8 HighN/A0%Sep 22, 2025
CVE-2025-57431: Download of Code Without Integrity Check8.8 HighN/A0%Sep 22, 2025
CVE-2025-43807: Improper Neutralization of Input During Web Page Generation5.4 Medium4.8 Medium0%Sep 22, 2025
CVE-2025-10807: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 22, 2025
CVE-2025-10806: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 22, 2025
CVE-2025-57682: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A1%Sep 22, 2025
CVE-2025-57605: Missing Authorization8.8 HighN/A0%Sep 22, 2025
CVE-2025-57602: Use of Hard-coded Credentials9.8 CriticalN/A1%Sep 22, 2025
CVE-2025-57601: Use of Hard-coded Credentials9.8 CriticalN/A0%Sep 22, 2025
CVE-2025-57433: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Sep 22, 2025
CVE-2025-57432: Missing Authentication for Critical Function9.8 CriticalN/A1%Sep 22, 2025
CVE-2025-57430: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Sep 22, 2025
CVE-2025-36202: Use of Externally-Controlled Format String7.5 HighN/A0%Sep 22, 2025
CVE-2025-36037: Server-Side Request Forgery (SSRF)5.4 MediumN/A0%Sep 22, 2025
CVE-2025-35042: Use of Default Credentials9.8 Critical9.3 Critical0%Sep 22, 2025
CVE-2025-35041: Improper Restriction of Excessive Authentication Attempts7.5 High7.7 High0%Sep 22, 2025
CVE-2025-10805: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 22, 2025
CVE-2025-10804: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 22, 2025
CVE-2025-9038: Improper Privilege ManagementN/A7.5 High0%Sep 22, 2025
CVE-2025-10803: Buffer Copy without Checking Size of Input8.8 High7.4 High1%Sep 22, 2025
CVE-2025-10802: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 22, 2025
CVE-2025-56075: Improper Neutralization of Special Elements used in an SQL Command5.4 MediumN/A0%Sep 22, 2025
CVE-2025-56074: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Sep 22, 2025
86076-86100 of 552652