The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-66183: Undefined Security WeaknessN/AN/AN/ANov 25, 2025
CVE-2025-66182: Undefined Security WeaknessN/AN/AN/ANov 25, 2025
CVE-2025-66181: Undefined Security WeaknessN/AN/AN/ANov 25, 2025
CVE-2025-66180: Undefined Security WeaknessN/AN/AN/ANov 25, 2025
CVE-2025-66179: Undefined Security WeaknessN/AN/AN/ANov 25, 2025
CVE-2025-10646: Missing Authorization4.3 MediumN/A0%Nov 25, 2025
CVE-2025-6389: Improper Control of Generation of Code9.8 CriticalN/A1%Nov 25, 2025
CVE-2025-59373: Incorrect Permission Assignment for Critical ResourceN/A8.5 High0%Nov 25, 2025
CVE-2025-9803: Improper Authentication8.8 HighN/A0%Nov 25, 2025
CVE-2025-65951: Exposure of Sensitive Information to an Unauthorized Actor8.7 HighN/A0%Nov 25, 2025
CVE-2025-65944: Insertion of Sensitive Information Into Sent DataN/A5.1 Medium0%Nov 25, 2025
CVE-2025-64761: Incorrect Privilege Assignment7.2 High7.5 High0%Nov 25, 2025
CVE-2025-65018: Out-of-bounds Write7.1 HighN/A0%Nov 25, 2025
CVE-2025-64720: Out-of-bounds Read7.1 HighN/A0%Nov 25, 2025
CVE-2025-64506: Out-of-bounds Read6.1 MediumN/A0%Nov 25, 2025
CVE-2025-64505: Out-of-bounds Read6.1 MediumN/A0%Nov 25, 2025
CVE-2025-62155: Server-Side Request Forgery (SSRF)8.5 HighN/A0%Nov 25, 2025
CVE-2025-10144: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 24, 2025
CVE-2025-63674: Improper Neutralization of Special Elements used in a Command6.8 MediumN/A0%Nov 24, 2025
CVE-2025-54563: Improper Access Control7.5 HighN/A0%Nov 24, 2025
CVE-2025-54347: Improper Limitation of a Pathname to a Restricted Directory9.9 CriticalN/A0%Nov 24, 2025
CVE-2025-54341: Use of Hard-coded Credentials5.3 MediumN/A0%Nov 24, 2025
CVE-2025-54338: Improper Access Control7.5 HighN/A0%Nov 24, 2025
CVE-2024-47856: Relative Path Traversal9.8 CriticalN/A0%Nov 24, 2025
CVE-2025-63498: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 24, 2025
81826-81850 of 599228