The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-10650: Improper Privilege ManagementN/A1.8 Low0%Sep 18, 2025
CVE-2025-10687: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 18, 2025
CVE-2025-55912: Unrestricted Upload of File with Dangerous Type7.3 HighN/A2%Sep 18, 2025
CVE-2025-50255: Cross-Site Request Forgery (CSRF)7.8 HighN/A0%Sep 18, 2025
CVE-2025-36146: Exposure of Sensitive System Information to an Unauthorized Control Sphere4.3 MediumN/A0%Sep 18, 2025
CVE-2025-36143: Improper Neutralization of Special Elements used in an OS Command4.7 MediumN/A0%Sep 18, 2025
CVE-2025-36139: Improper Neutralization of Input During Web Page Generation5.5 MediumN/A0%Sep 18, 2025
CVE-2025-10676: Improper Authorization4.3 Medium2.1 Low0%Sep 18, 2025
CVE-2025-10675: Improper Authorization4.3 Medium2.1 Low0%Sep 18, 2025
CVE-2025-10674: Improper Authorization4.3 Medium2.1 Low0%Sep 18, 2025
CVE-2023-53421: NULL Pointer Dereference5.5 MediumN/A0%Sep 18, 2025
CVE-2023-49367: Exposure of Sensitive Information to an Unauthorized Actor8.8 HighN/A0%Sep 18, 2025
CVE-2022-50418: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Sep 18, 2025
CVE-2022-50407: Uncontrolled Recursion5.5 MediumN/A0%Sep 18, 2025
CVE-2022-50403: Undefined Security WeaknessN/AN/A0%Sep 18, 2025
CVE-2023-53447: Concurrent Execution using Shared Resource with Improper Synchronization4.7 MediumN/A0%Sep 18, 2025
CVE-2023-53446: Use After Free7.8 HighN/A0%Sep 18, 2025
CVE-2023-53445: Undefined Security Weakness7.8 HighN/A0%Sep 18, 2025
CVE-2023-53444: NULL Pointer Dereference5.5 MediumN/A0%Sep 18, 2025
CVE-2023-53443: Undefined Security Weakness5.5 MediumN/A0%Sep 18, 2025
CVE-2023-53442: NULL Pointer Dereference5.5 MediumN/A0%Sep 18, 2025
CVE-2023-53441: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Sep 18, 2025
CVE-2023-53440: NULL Pointer Dereference7.8 HighN/A0%Sep 18, 2025
CVE-2023-53439: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Sep 18, 2025
CVE-2023-53438: Undefined Security Weakness5.5 MediumN/A0%Sep 18, 2025
86301-86325 of 559420