The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-39822: Undefined Security Weakness5.5 MediumN/A0%Sep 16, 2025
CVE-2025-39821: Out-of-bounds Write7.8 HighN/A0%Sep 16, 2025
CVE-2025-39820: NULL Pointer Dereference5.5 MediumN/A0%Sep 16, 2025
CVE-2025-39818: Out-of-bounds Write7.8 HighN/A0%Sep 16, 2025
CVE-2025-39817: Out-of-bounds Read7.1 HighN/A0%Sep 16, 2025
CVE-2025-39816: Undefined Security Weakness5.5 MediumN/A0%Sep 16, 2025
CVE-2025-39815: Undefined Security Weakness7.8 HighN/A0%Sep 16, 2025
CVE-2025-39814: NULL Pointer Dereference5.5 MediumN/A0%Sep 16, 2025
CVE-2025-39811: NULL Pointer Dereference5.5 MediumN/A0%Sep 16, 2025
CVE-2025-39810: Out-of-bounds Write7.8 HighN/A0%Sep 16, 2025
CVE-2025-39809: Out-of-bounds Write8.4 HighN/A0%Sep 16, 2025
CVE-2025-39807: NULL Pointer Dereference5.5 MediumN/A0%Sep 16, 2025
CVE-2025-39806: Out-of-bounds Read8.8 HighN/A0%Sep 16, 2025
CVE-2025-39805: Undefined Security Weakness5.5 MediumN/A0%Sep 16, 2025
CVE-2025-10535: Exposure of Sensitive Information to an Unauthorized ActorN/AN/A0%Sep 16, 2025
CVE-2025-10534: Improper Neutralization of Input During Web Page GenerationN/AN/A0%Sep 16, 2025
CVE-2025-8446: Missing Authorization4.3 MediumN/A0%Sep 16, 2025
CVE-2025-7744: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Sep 16, 2025
CVE-2025-7743: Cleartext Transmission of Sensitive Information9.6 CriticalN/A0%Sep 16, 2025
CVE-2025-6575: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Sep 16, 2025
CVE-2025-56706: Improper Neutralization of Special Elements used in a Command8.0 HighN/A2%Sep 16, 2025
CVE-2025-56697: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Sep 16, 2025
CVE-2024-12913: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Sep 16, 2025
CVE-2025-41249: Improper Authorization7.5 HighN/A0%Sep 16, 2025
CVE-2025-41248: Authentication Bypass by Alternate Name7.5 HighN/A0%Sep 16, 2025
86651-86675 of 775503