The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-13027: Improper Restriction of Operations within the Bounds of a Memory Buffer8.1 HighN/A0%Nov 11, 2025
CVE-2025-13026: Improper Check or Handling of Exceptional Conditions9.8 CriticalN/A0%Nov 11, 2025
CVE-2025-13025: Incorrect Default Permissions7.5 HighN/A0%Nov 11, 2025
CVE-2025-13024: Compiler Optimization Removal or Modification of Security-critical Code9.8 CriticalN/A0%Nov 11, 2025
CVE-2025-13023: Improper Check or Handling of Exceptional Conditions9.8 CriticalN/A0%Nov 11, 2025
CVE-2025-13022: Improper Check or Handling of Exceptional Conditions9.8 CriticalN/A0%Nov 11, 2025
CVE-2025-13021: Improper Check or Handling of Exceptional Conditions9.8 CriticalN/A0%Nov 11, 2025
CVE-2025-13020: Use After Free8.8 HighN/A0%Nov 11, 2025
CVE-2025-13019: Permissive Cross-domain Policy with Untrusted Domains8.1 HighN/A0%Nov 11, 2025
CVE-2025-13018: Authentication Bypass Using an Alternate Path or Channel8.1 HighN/A0%Nov 11, 2025
CVE-2025-13017: Permissive Cross-domain Policy with Untrusted Domains8.1 HighN/A0%Nov 11, 2025
CVE-2025-13016: Improper Check or Handling of Exceptional Conditions7.5 HighN/A0%Nov 11, 2025
CVE-2025-13015: Authentication Bypass by Spoofing3.4 LowN/A0%Nov 11, 2025
CVE-2025-13014: Use After Free8.8 HighN/A0%Nov 11, 2025
CVE-2025-13013: Authentication Bypass Using an Alternate Path or Channel6.1 MediumN/A0%Nov 11, 2025
CVE-2025-13012: Concurrent Execution using Shared Resource with Improper Synchronization7.5 HighN/A0%Nov 11, 2025
CVE-2025-10918: Incorrect Default Permissions7.1 HighN/A0%Nov 11, 2025
CVE-2025-10905: Protection Mechanism Failure4.4 MediumN/A0%Nov 11, 2025
CVE-2025-11959: Files or Directories Accessible to External Parties8.1 HighN/A0%Nov 11, 2025
CVE-2024-57695: Improper Neutralization of Special Elements used in a Command7.7 HighN/A0%Nov 11, 2025
CVE-2025-9227: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Nov 11, 2025
CVE-2025-9223: Improper Neutralization of Special Elements used in a Command8.8 HighN/A4%Nov 11, 2025
CVE-2025-12101: Improper Neutralization of Input During Web Page GenerationN/A5.9 Medium25%Nov 11, 2025
CVE-2025-11862: Incorrect AuthorizationN/A8.4 High0%Nov 11, 2025
CVE-2025-11697: Exposure of Sensitive Information to an Unauthorized ActorN/A8.9 High0%Nov 11, 2025
82726-82750 of 596643