The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-42884: Improper Neutralization of Special Elements in Data Query Logic6.5 MediumN/A0%Nov 11, 2025
CVE-2025-42883: Unrestricted Upload of File with Dangerous Type2.7 LowN/A0%Nov 11, 2025
CVE-2025-42882: Missing Authorization4.3 MediumN/A0%Nov 11, 2025
CVE-2025-31719: Undefined Security Weakness5.1 MediumN/A0%Nov 11, 2025
CVE-2025-64529: Allocation of Resources Without Limits or Throttling6.5 Medium2.7 Low0%Nov 10, 2025
CVE-2025-64522: Server-Side Request Forgery (SSRF)9.1 CriticalN/A0%Nov 10, 2025
CVE-2025-64519: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Nov 10, 2025
CVE-2025-63678: Unrestricted Upload of File with Dangerous Type7.2 HighN/A0%Nov 10, 2025
CVE-2025-12542: Undefined Security WeaknessN/AN/AN/ANov 10, 2025
CVE-2025-11892: Improper Neutralization of Input During Web Page Generation9.6 Critical8.6 High0%Nov 10, 2025
CVE-2025-11578: Improper Link Resolution Before File Access7.2 High7.5 High0%Nov 10, 2025
CVE-2021-4462: Unrestricted Upload of File with Dangerous Type9.8 Critical9.3 Critical19%Nov 10, 2025
CVE-2018-25124: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.7 High1%Nov 10, 2025
CVE-2025-64518: Improper Restriction of XML External Entity Reference7.5 HighN/A0%Nov 10, 2025
CVE-2025-64513: Improper AuthenticationN/A9.3 Critical0%Nov 10, 2025
CVE-2025-64512: Deserialization of Untrusted Data8.6 HighN/A0%Nov 10, 2025
CVE-2025-64509: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Nov 10, 2025
CVE-2025-64508: Allocation of Resources Without Limits or Throttling7.5 HighN/A0%Nov 10, 2025
CVE-2025-64507: Improper Privilege Management7.8 High8.6 High0%Nov 10, 2025
CVE-2025-64504: Exposure of Sensitive Information Through Data Queries5.0 MediumN/A0%Nov 10, 2025
CVE-2025-64502: Insertion of Sensitive Information Into Sent DataN/A6.9 Medium0%Nov 10, 2025
CVE-2025-64501: Improper Neutralization of Input During Web Page Generation7.6 HighN/A0%Nov 10, 2025
CVE-2025-64484: Improper Neutralization of HTTP Headers for Scripting Syntax8.5 HighN/A0%Nov 10, 2025
CVE-2025-64183: Use After Free7.5 High5.5 Medium0%Nov 10, 2025
CVE-2025-64182: Buffer Copy without Checking Size of Input7.8 High5.5 Medium0%Nov 10, 2025
82776-82800 of 715808