The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2024-44657: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2024-44653: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2024-44651: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2025-34323: Incorrect Permission Assignment for Critical Resource7.8 High8.5 High0%Nov 17, 2025
CVE-2025-34322: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High0%Nov 17, 2025
CVE-2025-63918: Improper Limitation of a Pathname to a Restricted Directory6.2 MediumN/A0%Nov 17, 2025
CVE-2025-63917: Improper Restriction of XML External Entity Reference7.1 HighN/A0%Nov 17, 2025
CVE-2025-62519: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Nov 17, 2025
CVE-2025-58410: Improper Handling of Insufficient Permissions or Privileges7.5 HighN/A0%Nov 17, 2025
CVE-2025-13319: Improper Input Validation8.8 HighN/A0%Nov 17, 2025
CVE-2025-13291: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Nov 17, 2025
CVE-2025-13290: Improper Neutralization of Special Elements used in an SQL Command8.8 High2.1 Low0%Nov 17, 2025
CVE-2025-13193: Incorrect Default Permissions5.5 MediumN/A0%Nov 17, 2025
CVE-2024-46336: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 17, 2025
CVE-2024-46334: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 17, 2025
CVE-2024-44652: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2024-44648: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2024-44647: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 17, 2025
CVE-2024-44644: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2024-44641: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Nov 17, 2025
CVE-2025-65083: Improper Certificate Validation3.2 LowN/A0%Nov 17, 2025
CVE-2025-64046: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 17, 2025
CVE-2025-63916: Improper Neutralization of Special Elements used in an OS Command8.1 HighN/A0%Nov 17, 2025
CVE-2025-63748: Unrestricted Upload of File with Dangerous Type8.8 HighN/A0%Nov 17, 2025
CVE-2025-63747: Weak Password Requirements9.8 CriticalN/A0%Nov 17, 2025
82326-82350 of 435805