The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-52670: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Nov 20, 2025
CVE-2025-52669: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Nov 20, 2025
CVE-2025-52668: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 20, 2025
CVE-2025-52667: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 20, 2025
CVE-2025-52666: Use of Externally-Controlled Format String2.7 LowN/A0%Nov 20, 2025
CVE-2025-48987: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 20, 2025
CVE-2025-48986: Improper Access Control8.8 HighN/A0%Nov 20, 2025
CVE-2025-35029: Improper Neutralization of Input During Web Page Generation3.5 Low4.8 Medium0%Nov 20, 2025
CVE-2025-63700: Undefined Security WeaknessN/AN/A0%Nov 20, 2025
CVE-2025-55128: Uncontrolled Resource Consumption6.5 MediumN/A0%Nov 20, 2025
CVE-2025-55127: Improper Neutralization of Whitespace5.4 MediumN/A0%Nov 20, 2025
CVE-2025-55126: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Nov 20, 2025
CVE-2025-10571: Authentication Bypass Using an Alternate Path or Channel9.6 Critical9.4 Critical0%Nov 20, 2025
CVE-2025-64524: Heap-based Buffer Overflow3.3 LowN/A0%Nov 20, 2025
CVE-2025-63889: Out-of-bounds Read7.5 HighN/A0%Nov 20, 2025
CVE-2025-63888: Improper Control of Filename for Include/Require Statement in PHP Program9.8 CriticalN/A0%Nov 20, 2025
CVE-2025-64428: Improper Neutralization of Special Elements in Output Used by a Downstream Component9.8 Critical8.9 High0%Nov 20, 2025
CVE-2025-64185: Insecure Inherited PermissionsN/A6.9 Medium0%Nov 20, 2025
CVE-2025-64027: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 20, 2025
CVE-2025-63848: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 20, 2025
CVE-2025-62724: UNIX Symbolic Link (Symlink) Following4.3 MediumN/A0%Nov 20, 2025
CVE-2025-62709: Weak Password Recovery Mechanism for Forgotten Password6.8 MediumN/A0%Nov 20, 2025
CVE-2025-52410: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Nov 20, 2025
CVE-2025-13437: Use of Incorrectly-Resolved Name or ReferenceN/A5.6 Medium0%Nov 20, 2025
CVE-2025-12121: Improper Neutralization of Special Elements used in an OS Command7.3 HighN/A0%Nov 20, 2025
82126-82150 of 744086