The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-36460: Buffer Access with Incorrect Length Value7.3 HighN/A0%Nov 17, 2025
CVE-2025-32089: Buffer Copy without Checking Size of Input8.8 HighN/A0%Nov 17, 2025
CVE-2025-31649: Use of Uninitialized Resource8.7 HighN/A0%Nov 17, 2025
CVE-2025-31361: Use of Uninitialized Resource8.7 HighN/A0%Nov 17, 2025
CVE-2025-13305: Buffer Copy without Checking Size of Input8.8 High7.4 High0%Nov 17, 2025
CVE-2025-13304: Buffer Copy without Checking Size of Input8.8 High7.4 High0%Nov 17, 2025
CVE-2025-13224: Access of Resource Using Incompatible Type8.8 HighN/A0%Nov 17, 2025
CVE-2025-13223: Access of Resource Using Incompatible TypeN/AN/A5%Nov 17, 2025
CVE-2025-64766: Use of Hard-coded Credentials5.3 MediumN/A0%Nov 17, 2025
CVE-2025-13303: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Nov 17, 2025
CVE-2025-13302: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Nov 17, 2025
CVE-2025-36118: Improper Clearing of Heap Memory Before Release7.5 HighN/A0%Nov 17, 2025
CVE-2025-13301: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 17, 2025
CVE-2025-13300: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 17, 2025
CVE-2025-36357: Absolute Path Traversal8.0 HighN/A0%Nov 17, 2025
CVE-2025-36299: Inclusion of Sensitive Information in Source Code4.3 MediumN/A0%Nov 17, 2025
CVE-2025-13299: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 17, 2025
CVE-2025-13298: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 17, 2025
CVE-2024-44664: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2024-44661: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 17, 2025
CVE-2024-44659: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Nov 17, 2025
CVE-2025-63292: Cleartext Transmission of Sensitive Information3.5 LowN/A0%Nov 17, 2025
CVE-2025-13216: Undefined Security WeaknessN/AN/AN/ANov 17, 2025
CVE-2024-46335: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Nov 17, 2025
CVE-2024-44663: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
82301-82325 of 435821