The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-64759: Improper Input Validation8.1 HighN/A0%Nov 19, 2025
CVE-2025-63211: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 19, 2025
CVE-2025-65099: Improper Control of Generation of Code9.8 Critical7.7 High0%Nov 19, 2025
CVE-2025-65095: Improper Neutralization of Input During Web Page GenerationN/A9.4 Critical0%Nov 19, 2025
CVE-2025-65089: Missing Authorization6.8 MediumN/A0%Nov 19, 2025
CVE-2025-65034: Authorization Bypass Through User-Controlled Key8.1 HighN/A0%Nov 19, 2025
CVE-2025-65033: Improper Authorization8.1 HighN/A0%Nov 19, 2025
CVE-2025-65032: Authorization Bypass Through User-Controlled Key6.5 MediumN/A0%Nov 19, 2025
CVE-2025-65031: Improper Authorization6.5 MediumN/A0%Nov 19, 2025
CVE-2025-65030: Improper Authorization7.1 HighN/A0%Nov 19, 2025
CVE-2025-65029: Improper Authorization8.1 HighN/A0%Nov 19, 2025
CVE-2025-65028: Improper Authorization6.5 MediumN/A0%Nov 19, 2025
CVE-2025-65026: Improper Control of Generation of Code6.1 MediumN/A0%Nov 19, 2025
CVE-2025-65025: Improper Limitation of a Pathname to a Restricted Directory8.2 HighN/A0%Nov 19, 2025
CVE-2025-65021: Improper Authorization9.1 CriticalN/A0%Nov 19, 2025
CVE-2025-65020: Improper Authorization6.5 MediumN/A0%Nov 19, 2025
CVE-2025-63210: Improper Authentication9.8 CriticalN/A0%Nov 19, 2025
CVE-2025-63209: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Nov 19, 2025
CVE-2025-63208: Cleartext Storage of Sensitive Information7.5 HighN/A0%Nov 19, 2025
CVE-2025-63207: Improper Authentication9.8 CriticalN/A0%Nov 19, 2025
CVE-2025-63206: Missing Authentication for Critical Function9.8 CriticalN/A0%Nov 19, 2025
CVE-2025-63205: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Nov 19, 2025
CVE-2025-13316: Use of Hard-coded Cryptographic Key8.1 High8.2 High72%Nov 19, 2025
CVE-2025-13315: Unprotected Alternate Channel9.8 Critical9.3 Critical82%Nov 19, 2025
CVE-2025-65019: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 19, 2025
82226-82250 of 744086