The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-52538: Integer Overflow or Wraparound8.0 HighN/A0%Nov 24, 2025
CVE-2025-48511: Improper Validation of Specified Index, Position, or Offset in Input5.5 MediumN/A0%Nov 24, 2025
CVE-2025-48510: Unexpected Status Code or Return Value7.1 HighN/A0%Nov 24, 2025
CVE-2025-36150: Use of a Broken or Risky Cryptographic Algorithm7.5 HighN/A0%Nov 24, 2025
CVE-2025-29933: Out-of-bounds Write5.5 MediumN/A0%Nov 24, 2025
CVE-2025-0007: Improper Adherence to Coding Standards5.7 MediumN/A0%Nov 24, 2025
CVE-2025-0003: Improper Resource Locking7.3 HighN/A0%Nov 24, 2025
CVE-2024-14007: Missing Authentication for Critical FunctionN/A8.7 High0%Nov 24, 2025
CVE-2023-7330: Unrestricted Upload of File with Dangerous TypeN/A9.3 Critical0%Nov 24, 2025
CVE-2018-25126: Use of Hard-coded CredentialsN/A9.3 Critical2%Nov 24, 2025
CVE-2025-64048: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 24, 2025
CVE-2025-64047: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 24, 2025
CVE-2025-63914: Improper Handling of Highly Compressed Data (Data Amplification)6.5 MediumN/A0%Nov 24, 2025
CVE-2025-56400: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Nov 24, 2025
CVE-2025-52539: Stack-based Buffer Overflow7.3 HighN/A0%Nov 24, 2025
CVE-2025-0005: Integer Overflow or Wraparound7.3 HighN/A0%Nov 24, 2025
CVE-2025-36112: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Nov 24, 2025
CVE-2025-13466: Uncontrolled Resource ConsumptionN/A5.5 Medium0%Nov 24, 2025
CVE-2025-13609: Use of Multiple Resources with Duplicate Identifier8.2 HighN/A0%Nov 24, 2025
CVE-2025-63958: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A0%Nov 24, 2025
CVE-2025-63953: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Nov 24, 2025
CVE-2025-63952: Cross-Site Request Forgery (CSRF)5.7 MediumN/A0%Nov 24, 2025
CVE-2025-63435: Missing Authentication for Critical Function4.3 MediumN/A0%Nov 24, 2025
CVE-2025-63434: Download of Code Without Integrity Check8.8 HighN/A0%Nov 24, 2025
CVE-2025-63433: Use of Hard-coded Credentials4.6 MediumN/A0%Nov 24, 2025
81851-81875 of 599228