The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-10690: Missing Authorization9.8 CriticalN/A1%Sep 19, 2025
CVE-2025-6198: Improper Verification of Cryptographic Signature7.2 HighN/A0%Sep 19, 2025
CVE-2025-30755: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 19, 2025
CVE-2025-59692: Incorrect Resource Transfer Between Spheres3.7 LowN/A0%Sep 18, 2025
CVE-2025-59691: Incorrect Resource Transfer Between Spheres3.7 LowN/A0%Sep 18, 2025
CVE-2025-59220: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Sep 18, 2025
CVE-2025-59216: Concurrent Execution using Shared Resource with Improper Synchronization7.0 HighN/A0%Sep 18, 2025
CVE-2025-59215: Use After Free7.0 HighN/A0%Sep 18, 2025
CVE-2025-54860: Improper Restriction of Excessive Authentication Attempts7.7 High6.9 Medium0%Sep 18, 2025
CVE-2025-54818: Cleartext Transmission of Sensitive Information8.0 High8.6 High0%Sep 18, 2025
CVE-2025-54810: Authentication Bypass by Capture-replay8.0 High8.6 High0%Sep 18, 2025
CVE-2025-54497: Incorrect Permission Assignment for Critical Resource8.1 High7.2 High0%Sep 18, 2025
CVE-2025-53969: Client-Side Enforcement of Server-Side Security8.8 High8.6 High0%Sep 18, 2025
CVE-2025-52873: Incorrect Permission Assignment for Critical Resource8.1 High7.2 High0%Sep 18, 2025
CVE-2025-10035: Improper Neutralization of Special Elements used in a Command9.8 CriticalN/A100%Sep 18, 2025
CVE-2025-57295: Weak Password Requirements8.0 HighN/A0%Sep 18, 2025
CVE-2025-57293: Improper Neutralization of Special Elements used in a Command8.8 HighN/A2%Sep 18, 2025
CVE-2025-55068: Integer Overflow or Wraparound8.2 High8.8 High0%Sep 18, 2025
CVE-2025-54807: Use of Hard-coded Cryptographic Key9.8 Critical9.3 Critical1%Sep 18, 2025
CVE-2025-54754: Use of Hard-coded Password8.0 High8.6 High0%Sep 18, 2025
CVE-2025-53947: Incorrect Default Permissions7.7 High6.9 Medium0%Sep 18, 2025
CVE-2025-47698: Cleartext Transmission of Sensitive InformationN/A8.6 High0%Sep 18, 2025
CVE-2025-30519: Use of Weak Credentials9.8 Critical9.3 Critical0%Sep 18, 2025
CVE-2025-10689: Improper Neutralization of Special Elements used in a Command6.3 Medium2.1 Low5%Sep 18, 2025
CVE-2025-59424: Improper Neutralization of Input During Web Page Generation7.3 HighN/A0%Sep 18, 2025
86276-86300 of 559420