The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-35433: Insufficient Session Expiration5.0 Medium2.3 Low0%Sep 17, 2025
CVE-2025-35432: Uncontrolled Resource Consumption5.3 Medium6.9 Medium1%Sep 17, 2025
CVE-2025-35431: Improper Neutralization of Special Elements used in an LDAP Query5.4 Medium5.3 Medium0%Sep 17, 2025
CVE-2025-35430: Improper Limitation of a Pathname to a Restricted Directory5.0 Medium5.3 Medium0%Sep 17, 2025
CVE-2025-10603: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 17, 2025
CVE-2025-10602: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 17, 2025
CVE-2025-10601: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 17, 2025
CVE-2025-10600: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium0%Sep 17, 2025
CVE-2025-10599: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 17, 2025
CVE-2025-10598: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Sep 17, 2025
CVE-2025-10597: Improper Neutralization of Special Elements used in an SQL Command7.3 High6.9 Medium0%Sep 17, 2025
CVE-2025-9862: Server-Side Request Forgery (SSRF)6.5 Medium6.1 Medium1%Sep 17, 2025
CVE-2025-57055: Server-Side Request Forgery (SSRF)6.5 MediumN/A0%Sep 17, 2025
CVE-2025-54390: Cross-Site Request Forgery (CSRF)6.3 MediumN/A0%Sep 17, 2025
CVE-2025-40933: Generation of Predictable Numbers or Identifiers7.5 HighN/A0%Sep 17, 2025
CVE-2025-10596: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Sep 17, 2025
CVE-2025-10595: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 17, 2025
CVE-2025-10205: Use of a One-Way Hash without a Salt8.8 High8.7 High0%Sep 17, 2025
CVE-2024-48842: Use of Hard-coded Credentials7.0 High7.3 High0%Sep 17, 2025
CVE-2023-53368: Concurrent Execution using Shared Resource with Improper Synchronization4.7 MediumN/A0%Sep 17, 2025
CVE-2023-53367: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Sep 17, 2025
CVE-2023-53366: NULL Pointer Dereference5.5 MediumN/A0%Sep 17, 2025
CVE-2023-53365: Undefined Security Weakness5.5 MediumN/A0%Sep 17, 2025
CVE-2023-53364: NULL Pointer Dereference5.5 MediumN/A0%Sep 17, 2025
CVE-2023-53363: Use After Free7.8 HighN/A0%Sep 17, 2025
86501-86525 of 395809