The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-9203: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 17, 2025
CVE-2025-10058: External Control of File Name or Path8.1 HighN/A1%Sep 17, 2025
CVE-2025-10057: Improper Control of Generation of Code8.8 HighN/A1%Sep 17, 2025
CVE-2025-10042: Improper Neutralization of Special Elements used in an SQL Command5.9 MediumN/A1%Sep 17, 2025
CVE-2025-9818: Unquoted Search Path or Element6.7 MediumN/A0%Sep 17, 2025
CVE-2025-59307: Unquoted Search Path or Element6.7 Medium8.4 High0%Sep 17, 2025
CVE-2025-58116: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High1%Sep 17, 2025
CVE-2025-55075: Hidden Functionality4.9 Medium6.9 Medium0%Sep 17, 2025
CVE-2025-10589: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High1%Sep 17, 2025
CVE-2025-10584: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Sep 17, 2025
CVE-2025-10188: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Sep 17, 2025
CVE-2025-10125: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6.4 MediumN/A0%Sep 17, 2025
CVE-2025-9891: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Sep 17, 2025
CVE-2025-9851: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 17, 2025
CVE-2025-9629: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Sep 17, 2025
CVE-2025-8394: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 17, 2025
CVE-2025-8153: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Sep 17, 2025
CVE-2025-10166: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Sep 17, 2025
CVE-2025-10143: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A1%Sep 17, 2025
CVE-2025-10050: Improper Limitation of a Pathname to a Restricted Directory6.6 MediumN/A1%Sep 17, 2025
CVE-2025-59518: Improper Neutralization of Special Elements used in an OS Command8.0 HighN/A1%Sep 17, 2025
CVE-2025-43804: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Sep 16, 2025
CVE-2025-37131: Improper Access Control4.9 MediumN/A0%Sep 16, 2025
CVE-2025-37130: Files or Directories Accessible to External Parties6.5 MediumN/A0%Sep 16, 2025
CVE-2025-37129: Improper Neutralization of Special Elements used in an OS Command6.7 MediumN/A0%Sep 16, 2025
86551-86575 of 389462