The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-65494: NULL Pointer Dereference7.5 HighN/A0%Nov 24, 2025
CVE-2025-65493: NULL Pointer Dereference7.5 HighN/A0%Nov 24, 2025
CVE-2025-41017: Missing AuthorizationN/A6.9 Medium0%Nov 24, 2025
CVE-2025-41016: Missing AuthorizationN/A8.7 High0%Nov 24, 2025
CVE-2025-12628: Undefined Security Weakness6.3 MediumN/A0%Nov 24, 2025
CVE-2025-40212: Undefined Security Weakness9.8 CriticalN/A0%Nov 24, 2025
CVE-2025-41729: Improper Validation of Specified Type of Input7.5 HighN/A0%Nov 24, 2025
CVE-2025-41087: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Nov 24, 2025
CVE-2025-12741: Improper Input ValidationN/A7.7 High0%Nov 24, 2025
CVE-2025-12740: Improper Input ValidationN/A7.7 High0%Nov 24, 2025
CVE-2025-12739: Improper Neutralization of Input During Web Page GenerationN/A7.3 High0%Nov 24, 2025
CVE-2025-13596: Generation of Error Message Containing Sensitive InformationN/A2.7 Low0%Nov 24, 2025
CVE-2025-13588: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Nov 24, 2025
CVE-2025-13586: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Nov 24, 2025
CVE-2025-13585: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 24, 2025
CVE-2025-12629: Undefined Security Weakness7.1 HighN/A0%Nov 24, 2025
CVE-2025-12569: Undefined Security Weakness4.7 MediumN/A0%Nov 24, 2025
CVE-2025-12394: Undefined Security Weakness5.9 MediumN/A0%Nov 24, 2025
CVE-2024-14015: Undefined Security Weakness7.1 HighN/A1%Nov 24, 2025
CVE-2025-7402: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Nov 24, 2025
CVE-2025-13584: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Nov 24, 2025
CVE-2025-13583: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 24, 2025
CVE-2025-13589: Improper Neutralization of Input During Web Page GenerationN/A5.1 Medium0%Nov 24, 2025
CVE-2025-13582: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 24, 2025
CVE-2025-13581: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Nov 24, 2025
81901-81925 of 402167