The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-58310: Access of Resource Using Incompatible Type8.0 HighN/A0%Nov 28, 2025
CVE-2025-58309: Undefined Security Weakness6.8 MediumN/A0%Nov 28, 2025
CVE-2025-58307: Use After Free6.4 MediumN/A0%Nov 28, 2025
CVE-2025-58303: Concurrent Execution using Shared Resource with Improper Synchronization8.4 HighN/A0%Nov 28, 2025
CVE-2025-58294: Undefined Security Weakness6.2 MediumN/A0%Nov 28, 2025
CVE-2025-66361: Improper Neutralization of Special Elements Used in a Template Engine6.5 Medium6.9 Medium0%Nov 28, 2025
CVE-2025-66360: Incorrect Authorization8.8 High6.9 Medium0%Nov 28, 2025
CVE-2025-66359: Improper Neutralization of Input During Web Page Generation8.5 HighN/A0%Nov 28, 2025
CVE-2025-13338: Undefined Security WeaknessN/AN/AN/ANov 27, 2025
CVE-2025-3261: Undefined Security WeaknessN/AN/A0%Nov 27, 2025
CVE-2025-12421: Incorrect Implementation of Authentication Algorithm9.9 CriticalN/A0%Nov 27, 2025
CVE-2025-12559: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Nov 27, 2025
CVE-2025-13765: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Nov 27, 2025
CVE-2025-13758: Exposure of Sensitive Information to an Unauthorized Actor3.5 LowN/A0%Nov 27, 2025
CVE-2025-13757: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Nov 27, 2025
CVE-2025-12419: Incorrect Implementation of Authentication Algorithm9.9 CriticalN/A0%Nov 27, 2025
CVE-2025-8890: Improper Neutralization of Special Elements used in an OS CommandN/A9.3 Critical1%Nov 27, 2025
CVE-2025-13692: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Nov 27, 2025
CVE-2025-12140: Improper Neutralization of Directives in Dynamically Evaluated CodeN/A9.3 Critical0%Nov 27, 2025
CVE-2025-12971: Incorrect Authorization4.3 MediumN/A0%Nov 27, 2025
CVE-2025-59454: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Nov 27, 2025
CVE-2025-59302: Improper Control of Generation of Code4.7 MediumN/A0%Nov 27, 2025
CVE-2025-54057: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6.1 MediumN/A0%Nov 27, 2025
CVE-2025-59890: Improper Limitation of a Pathname to a Restricted Directory7.3 HighN/A0%Nov 27, 2025
CVE-2025-13742: Improper Encoding or Escaping of Output6.1 Medium2.4 Low0%Nov 27, 2025
81601-81625 of 742608