The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-12143: Stack-based Buffer Overflow6.1 Medium6.9 Medium0%Nov 28, 2025
CVE-2025-13771: Relative Path Traversal6.5 Medium7.1 High0%Nov 28, 2025
CVE-2025-13770: Improper Neutralization of Special Elements used in an SQL Command6.5 Medium7.1 High0%Nov 28, 2025
CVE-2025-13769: Improper Neutralization of Special Elements used in an SQL Command6.5 Medium7.1 High0%Nov 28, 2025
CVE-2025-13768: Authorization Bypass Through User-Controlled Key7.5 High7.7 High0%Nov 28, 2025
CVE-2025-66386: Relative Path Traversal4.1 MediumN/A0%Nov 28, 2025
CVE-2025-66385: External Control of Assumed-Immutable Web ParameterN/A9.4 Critical0%Nov 28, 2025
CVE-2025-66384: Incorrect Provision of Specified Functionality8.2 HighN/A0%Nov 28, 2025
CVE-2025-66382: Inefficient Algorithmic Complexity2.9 LowN/A0%Nov 28, 2025
CVE-2025-66372: Improper Restriction of XML External Entity Reference2.8 LowN/A0%Nov 28, 2025
CVE-2025-66371: Improper Restriction of XML External Entity Reference5.0 MediumN/A0%Nov 28, 2025
CVE-2025-66370: Improper Restriction of XML External Entity Reference5.0 MediumN/A0%Nov 28, 2025
CVE-2025-64312: Exposure of Sensitive Information to an Unauthorized Actor4.9 MediumN/A0%Nov 28, 2025
CVE-2025-58311: Use After Free5.8 MediumN/A0%Nov 28, 2025
CVE-2025-58308: Improperly Implemented Security Check for Standard7.3 HighN/A0%Nov 28, 2025
CVE-2025-58305: Exposure of Sensitive Information to an Unauthorized Actor6.2 MediumN/A0%Nov 28, 2025
CVE-2025-58304: Undefined Security Weakness4.9 MediumN/A0%Nov 28, 2025
CVE-2025-58302: Undefined Security Weakness8.4 HighN/A0%Nov 28, 2025
CVE-2025-13737: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Nov 28, 2025
CVE-2025-64315: Undefined Security Weakness4.4 MediumN/A0%Nov 28, 2025
CVE-2025-64314: Access of Resource Using Incompatible Type9.3 CriticalN/A0%Nov 28, 2025
CVE-2025-64313: Concurrent Execution using Shared Resource with Improper Synchronization5.5 MediumN/A0%Nov 28, 2025
CVE-2025-64311: Exposure of Sensitive Information to an Unauthorized Actor5.1 MediumN/A0%Nov 28, 2025
CVE-2025-58316: Concurrent Execution using Shared Resource with Improper Synchronization5.5 MediumN/A0%Nov 28, 2025
CVE-2025-58315: Undefined Security Weakness5.5 MediumN/A0%Nov 28, 2025
81576-81600 of 742608