The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-59693: Improper Privilege Management9.8 CriticalN/A1%Dec 2, 2025
CVE-2025-13876: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium1.9 Low0%Dec 2, 2025
CVE-2025-13875: Improper Limitation of a Pathname to a Restricted Directory6.3 Medium2.1 Low0%Dec 2, 2025
CVE-2025-13505: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Dec 2, 2025
CVE-2025-65858: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Dec 2, 2025
CVE-2025-41086: Authorization Bypass Through User-Controlled Key6.5 Medium6.9 Medium0%Dec 2, 2025
CVE-2025-41066: Exposure of Sensitive Information to an Unauthorized Actor5.3 Medium6.9 Medium0%Dec 2, 2025
CVE-2025-41015: Exposure of Sensitive Information to an Unauthorized Actor7.5 High6.9 Medium0%Dec 2, 2025
CVE-2025-41014: Exposure of Sensitive Information to an Unauthorized Actor7.5 High6.9 Medium0%Dec 2, 2025
CVE-2025-41013: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical8.7 High0%Dec 2, 2025
CVE-2025-13731: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 2, 2025
CVE-2025-13295: Insertion of Sensitive Information Into Sent Data7.5 HighN/A0%Dec 2, 2025
CVE-2025-41012: Missing Authorization5.3 Medium8.7 High0%Dec 2, 2025
CVE-2025-40700: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Dec 2, 2025
CVE-2025-13879: Improper Limitation of a Pathname to a Restricted Directory2.7 Low5.1 Medium0%Dec 2, 2025
CVE-2025-12465: Improper Neutralization of Special Elements used in an SQL CommandN/A8.6 High0%Dec 2, 2025
CVE-2025-11789: Out-of-bounds Read7.5 High7.1 High0%Dec 2, 2025
CVE-2025-11788: Heap-based Buffer Overflow9.8 Critical8.5 High0%Dec 2, 2025
CVE-2025-11787: Improper Neutralization of Special Elements used in an OS Command8.8 High8.5 High0%Dec 2, 2025
CVE-2025-11786: Stack-based Buffer Overflow9.8 Critical8.5 High0%Dec 2, 2025
CVE-2025-11785: Stack-based Buffer Overflow9.8 Critical8.5 High0%Dec 2, 2025
CVE-2025-11784: Stack-based Buffer Overflow9.8 Critical8.5 High0%Dec 2, 2025
CVE-2025-11783: Stack-based Buffer Overflow9.8 Critical8.5 High0%Dec 2, 2025
CVE-2025-11782: Stack-based Buffer Overflow9.8 Critical8.5 High0%Dec 2, 2025
CVE-2025-11781: Use of Hard-coded Cryptographic Key7.8 High8.6 High0%Dec 2, 2025
81376-81400 of 398159