The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-64718: Improperly Controlled Modification of Object Prototype Attributes5.3 MediumN/A0%Nov 13, 2025
CVE-2025-64717: Improper Authentication9.8 Critical7.4 High0%Nov 13, 2025
CVE-2025-64714: Relative Path Traversal5.8 MediumN/A0%Nov 13, 2025
CVE-2025-64703: Exposure of Sensitive Information to an Unauthorized Actor6.3 MediumN/A0%Nov 13, 2025
CVE-2025-64525: Server-Side Request Forgery (SSRF)6.5 MediumN/A1%Nov 13, 2025
CVE-2025-64511: Server-Side Request Forgery (SSRF)7.4 HighN/A0%Nov 13, 2025
CVE-2025-62484: Inefficient Regular Expression Complexity8.1 HighN/A0%Nov 13, 2025
CVE-2025-60689: Improper Neutralization of Special Elements used in a Command5.4 MediumN/A18%Nov 13, 2025
CVE-2025-60688: Stack-based Buffer Overflow6.5 MediumN/A1%Nov 13, 2025
CVE-2025-60687: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A7%Nov 13, 2025
CVE-2025-60686: Stack-based Buffer Overflow5.1 MediumN/A0%Nov 13, 2025
CVE-2025-60685: Stack-based Buffer Overflow5.1 MediumN/A0%Nov 13, 2025
CVE-2025-60684: Stack-based Buffer Overflow6.5 MediumN/A1%Nov 13, 2025
CVE-2025-60683: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A1%Nov 13, 2025
CVE-2025-60682: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A1%Nov 13, 2025
CVE-2025-52186: Server-Side Request Forgery (SSRF)6.5 MediumN/A0%Nov 13, 2025
CVE-2025-13120: Use After Free5.3 Medium1.9 Low0%Nov 13, 2025
CVE-2025-64741: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.1 HighN/A0%Nov 13, 2025
CVE-2025-64740: Improper Verification of Cryptographic Signature7.5 HighN/A0%Nov 13, 2025
CVE-2025-64739: External Control of File Name or Path4.3 MediumN/A0%Nov 13, 2025
CVE-2025-64738: External Control of File Name or Path5.0 MediumN/A0%Nov 13, 2025
CVE-2025-62483: Improper Removal of Sensitive Information Before Storage or Transfer5.3 MediumN/A0%Nov 13, 2025
CVE-2025-62482: Improper Neutralization of Input During Web Page Generation4.3 MediumN/A0%Nov 13, 2025
CVE-2025-30669: Improper Certificate Validation4.8 MediumN/A0%Nov 13, 2025
CVE-2025-30662: Reliance on File Name or Extension of Externally-Supplied File6.6 MediumN/A0%Nov 13, 2025
82426-82450 of 554722