The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-12085: Missing Authorization4.3 MediumN/A0%Nov 21, 2025
CVE-2025-12023: Missing Authorization4.3 MediumN/A0%Nov 21, 2025
CVE-2025-12022: Missing Authorization4.3 MediumN/A0%Nov 21, 2025
CVE-2025-11368: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A1%Nov 21, 2025
CVE-2025-64310: Improper Restriction of Excessive Authentication Attempts9.8 Critical9.3 Critical0%Nov 21, 2025
CVE-2025-64762: Use of Cache Containing Sensitive Information9.1 Critical8.0 High0%Nov 21, 2025
CVE-2025-64755: Improper Neutralization of Special Elements used in an OS Command9.8 Critical8.7 High1%Nov 21, 2025
CVE-2025-64751: Improper Authorization8.8 High5.8 Medium0%Nov 21, 2025
CVE-2025-62426: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Nov 21, 2025
CVE-2025-62372: Improper Validation of Array Index6.5 Medium8.3 High0%Nov 21, 2025
CVE-2025-62164: Improper Input Validation8.8 HighN/A1%Nov 21, 2025
CVE-2025-13485: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 21, 2025
CVE-2025-64660: Improper Access Control8.0 HighN/A1%Nov 20, 2025
CVE-2025-64655: Improper Authorization8.8 HighN/A0%Nov 20, 2025
CVE-2025-62459: Improper Neutralization of Input During Web Page Generation8.3 HighN/A0%Nov 20, 2025
CVE-2025-62207: Server-Side Request Forgery (SSRF)8.6 HighN/A1%Nov 20, 2025
CVE-2025-59245: Deserialization of Untrusted Data9.8 CriticalN/A1%Nov 20, 2025
CVE-2025-49752: Authentication Bypass by Capture-replay10.0 CriticalN/A1%Nov 20, 2025
CVE-2025-36072: Deserialization of Untrusted Data8.8 HighN/A0%Nov 20, 2025
CVE-2025-13484: Improper Neutralization of Input During Web Page Generation2.4 Low1.9 Low0%Nov 20, 2025
CVE-2025-61138: Insertion of Sensitive Information into Externally-Accessible File or Directory7.5 HighN/A0%Nov 20, 2025
CVE-2025-36160: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Nov 20, 2025
CVE-2025-36159: Improper Output Neutralization for Logs6.2 MediumN/A0%Nov 20, 2025
CVE-2025-36158: Uncontrolled Recursion5.1 MediumN/A0%Nov 20, 2025
CVE-2025-36153: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 20, 2025
82101-82125 of 475154