The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-0645: Unrestricted Upload of File with Dangerous Type7.2 HighN/A0%Nov 20, 2025
CVE-2025-0643: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Nov 20, 2025
CVE-2025-13424: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Nov 20, 2025
CVE-2025-13423: Unrestricted Upload of File with Dangerous Type4.7 Medium2.0 Low0%Nov 20, 2025
CVE-2025-13422: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 20, 2025
CVE-2025-4042: Undefined Security WeaknessN/AN/AN/ANov 19, 2025
CVE-2025-13421: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 19, 2025
CVE-2025-13420: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 19, 2025
CVE-2025-13415: Improper Neutralization of Input During Web Page Generation3.5 Low5.1 Medium0%Nov 19, 2025
CVE-2025-11884: Improper Neutralization of Input During Web Page GenerationN/A2.3 Low0%Nov 19, 2025
CVE-2025-11001: Improper Limitation of a Pathname to a Restricted Directory7.8 HighN/A0%Nov 19, 2025
CVE-2025-63719: Improper Neutralization of Special Elements used in an SQL Command7.3 HighN/A0%Nov 19, 2025
CVE-2025-63371: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Nov 19, 2025
CVE-2025-58181: Allocation of Resources Without Limits or Throttling5.3 MediumN/A0%Nov 19, 2025
CVE-2025-47914: Out-of-bounds Read5.3 MediumN/A0%Nov 19, 2025
CVE-2025-13412: Improper Neutralization of Input During Web Page Generation2.4 Low1.9 Low0%Nov 19, 2025
CVE-2025-13411: Unrestricted Upload of File with Dangerous Type4.7 Medium2.0 Low0%Nov 19, 2025
CVE-2025-13410: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 19, 2025
CVE-2025-13147: Server-Side Request Forgery (SSRF)5.3 MediumN/A0%Nov 19, 2025
CVE-2025-65103: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Nov 19, 2025
CVE-2025-63932: Improper Neutralization of Special Elements used in an OS Command7.3 HighN/A0%Nov 19, 2025
CVE-2025-63214: Improper Access Control6.5 MediumN/A0%Nov 19, 2025
CVE-2025-63213: Improper Input Validation9.8 CriticalN/A0%Nov 19, 2025
CVE-2025-63212: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Nov 19, 2025
CVE-2025-51663: Authentication Bypass by Primary Weakness7.5 HighN/A0%Nov 19, 2025
82201-82225 of 744086