The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-63679: Buffer Copy without Checking Size of Input7.5 HighN/A0%Nov 12, 2025
CVE-2025-61667: Incorrect Default PermissionsN/A7.0 High0%Nov 12, 2025
CVE-2025-60646: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 12, 2025
CVE-2025-57812: Out-of-bounds Read3.7 LowN/A0%Nov 12, 2025
CVE-2025-57310: Cross-Site Request Forgery (CSRF)8.8 HighN/A0%Nov 12, 2025
CVE-2025-56385: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Nov 12, 2025
CVE-2025-13057: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Nov 12, 2025
CVE-2024-47866: Improper Input Validation7.5 HighN/A0%Nov 12, 2025
CVE-2024-45301: Improper Input Validation5.3 MediumN/A0%Nov 12, 2025
CVE-2025-65002: Incorrect Authorization7.5 HighN/A0%Nov 12, 2025
CVE-2025-65001: Out-of-bounds Write8.2 HighN/A0%Nov 12, 2025
CVE-2025-63811: Uncontrolled Resource Consumption7.5 HighN/A0%Nov 12, 2025
CVE-2025-60645: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Nov 12, 2025
CVE-2025-25236: Observable Response Discrepancy5.3 MediumN/A0%Nov 12, 2025
CVE-2025-20379: Exposure of Sensitive Information to an Unauthorized Actor3.5 LowN/A0%Nov 12, 2025
CVE-2025-20378: URL Redirection to Untrusted Site3.1 LowN/A0%Nov 12, 2025
CVE-2025-63419: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 12, 2025
CVE-2025-59491: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 12, 2025
CVE-2025-59089: Allocation of Resources Without Limits or Throttling5.9 MediumN/A0%Nov 12, 2025
CVE-2025-59088: Server-Side Request Forgery (SSRF)8.6 HighN/A0%Nov 12, 2025
CVE-2025-52331: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Nov 12, 2025
CVE-2025-2843: Incorrect Privilege Assignment8.8 HighN/A0%Nov 12, 2025
CVE-2025-13042: Out-of-bounds Write8.8 HighN/A0%Nov 12, 2025
CVE-2025-11797: Use After Free7.8 HighN/A0%Nov 12, 2025
CVE-2025-11795: Out-of-bounds Write7.8 HighN/A0%Nov 12, 2025
82526-82550 of 594173