The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2022-50379: Concurrent Execution using Shared Resource with Improper Synchronization4.7 MediumN/A0%Sep 18, 2025
CVE-2022-50375: Undefined Security Weakness5.5 MediumN/A0%Sep 18, 2025
CVE-2025-10667: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 18, 2025
CVE-2025-10666: Buffer Copy without Checking Size of Input8.8 High7.4 High3%Sep 18, 2025
CVE-2025-40678: Unrestricted Upload of File with Dangerous TypeN/A5.3 Medium0%Sep 18, 2025
CVE-2025-40677: Improper Neutralization of Special Elements used in an SQL CommandN/A8.7 High1%Sep 18, 2025
CVE-2025-10665: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 18, 2025
CVE-2025-10664: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 18, 2025
CVE-2025-10207: Improper Validation of Specified Type of Input7.2 High7.5 High0%Sep 18, 2025
CVE-2024-48851: Improper Validation of Specified Type of Input7.2 High7.5 High1%Sep 18, 2025
CVE-2024-25011: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Sep 18, 2025
CVE-2024-13151: Undefined Security Weakness9.8 CriticalN/A0%Sep 18, 2025
CVE-2025-10663: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 18, 2025
CVE-2025-10662: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Sep 18, 2025
CVE-2025-9992: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 18, 2025
CVE-2025-8565: Missing Authorization8.1 HighN/A0%Sep 18, 2025
CVE-2025-30187: Loop with Unreachable Exit Condition3.7 LowN/A0%Sep 18, 2025
CVE-2025-6237: External Control of File Name or Path9.8 CriticalN/A0%Sep 18, 2025
CVE-2025-0547: Improper Neutralization of Input During Web Page Generation4.7 MediumN/A0%Sep 18, 2025
CVE-2025-10493: Authorization Bypass Through User-Controlled Key5.3 MediumN/A1%Sep 18, 2025
CVE-2025-9083: Undefined Security Weakness9.8 CriticalN/A1%Sep 18, 2025
CVE-2025-8942: Undefined Security Weakness9.1 CriticalN/A0%Sep 18, 2025
CVE-2025-5305: Undefined Security Weakness9.8 CriticalN/A0%Sep 18, 2025
CVE-2023-49565: Improper Neutralization of Special Elements used in a Command8.4 HighN/A1%Sep 18, 2025
CVE-2023-49564: Authentication Bypass Using an Alternate Path or Channel8.8 HighN/A0%Sep 18, 2025
86426-86450 of 395809