The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2021-4468: Missing Authentication for Critical FunctionN/A8.7 High0%Nov 14, 2025
CVE-2021-4467: Uncontrolled Resource ConsumptionN/A8.7 High0%Nov 14, 2025
CVE-2021-4466: Improper Neutralization of Special Elements used in an OS CommandN/A8.7 High1%Nov 14, 2025
CVE-2021-4465: Uncontrolled Resource ConsumptionN/A8.7 High0%Nov 14, 2025
CVE-2018-25125: Buffer Copy without Checking Size of InputN/A8.7 High0%Nov 14, 2025
CVE-2016-15056: Insertion of Sensitive Information into Externally-Accessible File or DirectoryN/A8.7 High1%Nov 14, 2025
CVE-2025-13187: Plaintext Storage of a Password5.3 Medium5.5 Medium0%Nov 14, 2025
CVE-2025-13186: Improper Neutralization of Input During Web Page Generation2.4 Low1.9 Low0%Nov 14, 2025
CVE-2025-64084: Improper Neutralization of Special Elements used in an SQL Command5.4 MediumN/A0%Nov 14, 2025
CVE-2025-63891: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Nov 14, 2025
CVE-2025-63745: NULL Pointer Dereference5.5 MediumN/A0%Nov 14, 2025
CVE-2025-63744: NULL Pointer Dereference4.3 MediumN/A0%Nov 14, 2025
CVE-2025-13185: Unrestricted Upload of File with Dangerous Type4.7 Medium2.0 Low0%Nov 14, 2025
CVE-2025-13182: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Nov 14, 2025
CVE-2025-63701: Heap-based Buffer Overflow6.8 MediumN/A0%Nov 14, 2025
CVE-2025-13181: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Nov 14, 2025
CVE-2025-13180: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)3.5 Low2.0 Low0%Nov 14, 2025
CVE-2025-13179: Cross-Site Request Forgery (CSRF)4.3 Medium2.1 Low0%Nov 14, 2025
CVE-2025-13033: Improper Validation of Syntactic Correctness of Input7.5 HighN/A0%Nov 14, 2025
CVE-2025-63680: Improper Limitation of a Pathname to a Restricted Directory8.6 HighN/A0%Nov 14, 2025
CVE-2025-63291: Incorrect Use of Privileged APIs5.4 MediumN/A0%Nov 14, 2025
CVE-2025-13178: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)3.5 Low2.0 Low0%Nov 14, 2025
CVE-2025-13177: Cross-Site Request Forgery (CSRF)4.3 Medium2.1 Low0%Nov 14, 2025
CVE-2025-13174: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Nov 14, 2025
CVE-2025-12187: Undefined Security WeaknessN/AN/AN/ANov 14, 2025
82351-82375 of 435667