The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2022-50366: Out-of-bounds Read7.1 HighN/A0%Sep 17, 2025
CVE-2022-50365: Undefined Security Weakness7.5 HighN/A1%Sep 17, 2025
CVE-2022-50364: NULL Pointer Dereference5.5 MediumN/A0%Sep 17, 2025
CVE-2022-50363: Use After Free9.8 CriticalN/A0%Sep 17, 2025
CVE-2022-50362: Undefined Security Weakness7.8 HighN/A0%Sep 17, 2025
CVE-2022-50361: NULL Pointer Dereference5.5 MediumN/A0%Sep 17, 2025
CVE-2022-50360: Undefined Security Weakness5.5 MediumN/A0%Sep 17, 2025
CVE-2022-50359: NULL Pointer Dereference5.5 MediumN/A0%Sep 17, 2025
CVE-2022-50358: Undefined Security Weakness4.2 MediumN/A0%Sep 17, 2025
CVE-2022-50357: Missing Release of Memory after Effective Lifetime5.5 MediumN/A0%Sep 17, 2025
CVE-2022-50356: NULL Pointer Dereference5.5 MediumN/A0%Sep 17, 2025
CVE-2022-50355: Missing Release of Memory after Effective Lifetime7.8 HighN/A0%Sep 17, 2025
CVE-2022-50354: NULL Pointer Dereference7.8 HighN/A0%Sep 17, 2025
CVE-2022-50353: NULL Pointer Dereference5.5 MediumN/A0%Sep 17, 2025
CVE-2025-59476: Improper Output Neutralization for Logs5.3 MediumN/A0%Sep 17, 2025
CVE-2025-59475: Missing Authorization4.3 MediumN/A0%Sep 17, 2025
CVE-2025-59474: Missing Authorization5.3 MediumN/A5%Sep 17, 2025
CVE-2025-55904: NULL Pointer Dereference4.0 MediumN/A0%Sep 17, 2025
CVE-2025-50709: Use of GET Request Method With Sensitive Query Strings4.3 MediumN/A0%Sep 17, 2025
CVE-2025-10594: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 17, 2025
CVE-2025-10593: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Sep 17, 2025
CVE-2025-8463: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Sep 17, 2025
CVE-2025-8077: Use of Default Password9.8 CriticalN/A1%Sep 17, 2025
CVE-2025-54467: Insufficiently Protected Credentials5.3 MediumN/A0%Sep 17, 2025
CVE-2025-53884: Use of a One-Way Hash without a Salt5.3 MediumN/A0%Sep 17, 2025
86526-86550 of 395809