The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-59797: Direct Request5.8 MediumN/A0%Sep 22, 2025
CVE-2025-10854: UNIX Symbolic Link (Symlink) Following8.1 HighN/A0%Sep 22, 2025
CVE-2025-10799: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2025
CVE-2025-10798: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2025
CVE-2025-10797: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2025
CVE-2025-10796: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2025
CVE-2025-9983: Missing Authentication for Critical FunctionN/A7.1 High1%Sep 22, 2025
CVE-2025-46711: NULL Pointer Dereference5.5 MediumN/A0%Sep 22, 2025
CVE-2025-10795: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 22, 2025
CVE-2025-10794: Improper Neutralization of Input During Web Page Generation4.3 Medium2.1 Low0%Sep 22, 2025
CVE-2025-9035: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 22, 2025
CVE-2025-25177: Use After Free5.1 MediumN/A0%Sep 22, 2025
CVE-2025-10793: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 22, 2025
CVE-2025-10792: Buffer Copy without Checking Size of Input8.8 High7.4 High3%Sep 22, 2025
CVE-2025-10009: Unrestricted Upload of File with Dangerous TypeN/A8.6 High1%Sep 22, 2025
CVE-2025-8079: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Sep 22, 2025
CVE-2025-10791: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 22, 2025
CVE-2025-10790: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 22, 2025
CVE-2025-5962: Improper Access Control7.7 HighN/A0%Sep 22, 2025
CVE-2025-10789: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2025
CVE-2025-10788: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 22, 2025
CVE-2025-0875: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Sep 22, 2025
CVE-2025-10787: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Sep 22, 2025
CVE-2025-10786: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 22, 2025
CVE-2025-9541: Undefined Security Weakness4.7 MediumN/A0%Sep 22, 2025
86101-86125 of 397021