The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-66224: Improper Control of Generation of Code8.8 High9.0 Critical0%Nov 29, 2025
CVE-2025-65892: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 29, 2025
CVE-2025-65540: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 29, 2025
CVE-2025-66223: Insufficient Session ExpirationN/A8.4 High0%Nov 29, 2025
CVE-2025-66221: Improper Handling of Windows Device Names5.3 Medium6.3 Medium0%Nov 29, 2025
CVE-2025-66217: Heap-based Buffer Overflow7.5 High8.8 High1%Nov 29, 2025
CVE-2025-66216: Incorrect Calculation of Buffer Size9.8 Critical9.3 Critical0%Nov 29, 2025
CVE-2025-61915: Improper Validation of Array Index6.0 MediumN/A0%Nov 29, 2025
CVE-2025-58436: Uncontrolled Resource Consumption5.1 MediumN/A0%Nov 29, 2025
CVE-2025-53939: Improper Input Validation6.3 MediumN/A0%Nov 29, 2025
CVE-2025-53900: Privilege Defined With Unsafe Actions6.5 MediumN/A0%Nov 29, 2025
CVE-2025-53899: Incorrectly Specified Destination in a Communication Channel7.2 HighN/A0%Nov 29, 2025
CVE-2025-53897: Cross-Site Request Forgery (CSRF)6.8 MediumN/A0%Nov 29, 2025
CVE-2025-53896: Insufficient Session Expiration7.1 HighN/A0%Nov 29, 2025
CVE-2025-66219: Improper Neutralization of Special Elements used in a Command9.8 Critical6.9 Medium0%Nov 29, 2025
CVE-2025-66201: Improper Input Validation8.1 High8.6 High0%Nov 29, 2025
CVE-2025-66036: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 29, 2025
CVE-2025-66034: XML Injection (aka Blind XPath Injection)6.3 MediumN/A0%Nov 29, 2025
CVE-2025-66027: Exposure of Sensitive Information to an Unauthorized Actor6.5 Medium7.1 High0%Nov 29, 2025
CVE-2025-65113: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Nov 29, 2025
CVE-2025-65112: Missing Authorization9.4 CriticalN/A0%Nov 29, 2025
CVE-2025-64715: Improper Access Control4.0 MediumN/A0%Nov 29, 2025
CVE-2025-13683: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Nov 28, 2025
CVE-2025-12183: Out-of-bounds ReadN/A8.8 High0%Nov 28, 2025
CVE-2025-59792: Cleartext Storage of Sensitive Information5.3 MediumN/A0%Nov 28, 2025
81551-81575 of 742608