The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-36134: Sensitive Cookie with Improper SameSite Attribute3.7 LowN/A0%Nov 25, 2025
CVE-2025-64693: Heap-based Buffer Overflow9.8 Critical9.3 Critical0%Nov 25, 2025
CVE-2025-62691: Stack-based Buffer Overflow9.8 Critical9.3 Critical0%Nov 25, 2025
CVE-2025-59485: Incorrect Default Permissions3.3 Low4.8 Medium0%Nov 25, 2025
CVE-2025-59372: Improper Limitation of a Pathname to a Restricted DirectoryN/A6.9 Medium0%Nov 25, 2025
CVE-2025-59371: Use of Insufficiently Random ValuesN/A7.5 High0%Nov 25, 2025
CVE-2025-59370: Improper Neutralization of Special Elements used in an OS CommandN/A7.5 High1%Nov 25, 2025
CVE-2025-59369: Improper Neutralization of Special Elements used in an SQL CommandN/A5.9 Medium0%Nov 25, 2025
CVE-2025-59368: Integer Underflow (Wrap or Wraparound)N/A6.0 Medium0%Nov 25, 2025
CVE-2025-59366: Improper Limitation of a Pathname to a Restricted DirectoryN/A9.2 Critical0%Nov 25, 2025
CVE-2025-59365: Stack-based Buffer OverflowN/A6.9 Medium0%Nov 25, 2025
CVE-2025-13502: Out-of-bounds Read7.5 HighN/A0%Nov 25, 2025
CVE-2025-13452: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Nov 25, 2025
CVE-2025-13414: Missing Authorization5.3 MediumN/A0%Nov 25, 2025
CVE-2025-13405: Missing Authorization5.3 MediumN/A0%Nov 25, 2025
CVE-2025-13404: Missing Authorization5.3 MediumN/A0%Nov 25, 2025
CVE-2025-13389: Authorization Bypass Through User-Controlled Key5.3 MediumN/A0%Nov 25, 2025
CVE-2025-13386: Missing Authorization5.3 MediumN/A0%Nov 25, 2025
CVE-2025-13385: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Nov 25, 2025
CVE-2025-13383: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 25, 2025
CVE-2025-13382: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Nov 25, 2025
CVE-2025-13380: External Control of File Name or Path6.5 MediumN/A0%Nov 25, 2025
CVE-2025-13376: Unrestricted Upload of File with Dangerous Type7.2 HighN/A0%Nov 25, 2025
CVE-2025-13370: Improper Neutralization of Special Elements used in an SQL Command4.9 MediumN/A0%Nov 25, 2025
CVE-2025-13311: Improper Neutralization of Input During Web Page Generation4.4 MediumN/A0%Nov 25, 2025
81776-81800 of 599228