The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-65107: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Nov 21, 2025
CVE-2025-65106: Improper Neutralization of Special Elements Used in a Template EngineN/A8.3 High1%Nov 21, 2025
CVE-2025-65102: Buffer Copy without Checking Size of InputN/A8.7 High0%Nov 21, 2025
CVE-2025-65092: Out-of-bounds ReadN/A6.9 Medium0%Nov 21, 2025
CVE-2025-43374: Stack-based Buffer Overflow4.3 MediumN/A0%Nov 21, 2025
CVE-2025-31266: User Interface (UI) Misrepresentation of Critical Information4.3 MediumN/A0%Nov 21, 2025
CVE-2025-31248: Improper Limitation of a Pathname to a Restricted Directory5.5 MediumN/A0%Nov 21, 2025
CVE-2025-31216: Improper Access Control2.4 LowN/A0%Nov 21, 2025
CVE-2025-11935: Inadequate Encryption Strength7.5 High6.3 Medium0%Nov 21, 2025
CVE-2025-0504: Incorrect Privilege Assignment5.4 Medium5.3 Medium0%Nov 21, 2025
CVE-2025-11087: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Nov 21, 2025
CVE-2025-36149: Improper Restriction of Rendered UI Layers or Frames6.3 MediumN/A0%Nov 21, 2025
CVE-2025-13524: Improper Resource Shutdown or Release5.7 Medium6.8 Medium0%Nov 21, 2025
CVE-2025-64767: Reusing a Nonce, Key Pair in Encryption9.1 CriticalN/A0%Nov 21, 2025
CVE-2025-64169: Unchecked Return Value4.9 Medium5.1 Medium0%Nov 21, 2025
CVE-2025-62626: Improper Handling of Insufficient Entropy in TRNGN/A7.2 High0%Nov 21, 2025
CVE-2025-62609: NULL Pointer Dereference7.5 High5.5 Medium0%Nov 21, 2025
CVE-2025-62608: Heap-based Buffer Overflow9.1 Critical5.5 Medium1%Nov 21, 2025
CVE-2025-54866: Incorrect Default Permissions5.5 Medium1.8 Low0%Nov 21, 2025
CVE-2025-48502: Improper Validation of Specified Index, Position, or Offset in Input5.5 MediumN/A0%Nov 21, 2025
CVE-2025-30201: External Control of File Name or Path7.7 HighN/A1%Nov 21, 2025
CVE-2025-29934: Incomplete Cleanup5.3 MediumN/A0%Nov 21, 2025
CVE-2025-64483: Improper Access ControlN/A5.3 Medium0%Nov 21, 2025
CVE-2025-13132: Improper Restriction of Rendered UI Layers or Frames7.4 HighN/A0%Nov 21, 2025
CVE-2025-13470: Use of Insufficiently Random Values7.5 High7.7 High0%Nov 21, 2025
81976-82000 of 569087