The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-20358: Missing Authentication for Critical Function9.4 CriticalN/A1%Nov 5, 2025
CVE-2025-20354: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A0%Nov 5, 2025
CVE-2025-20343: Incorrect Comparison8.6 HighN/A0%Nov 5, 2025
CVE-2025-20305: Insufficient Granularity of Access Control4.3 MediumN/A0%Nov 5, 2025
CVE-2025-20304: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 5, 2025
CVE-2025-20303: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 5, 2025
CVE-2025-20289: Improper Neutralization of Input During Web Page Generation4.8 MediumN/A0%Nov 5, 2025
CVE-2025-63601: Unrestricted Upload of File with Dangerous Type9.9 CriticalN/A0%Nov 5, 2025
CVE-2025-61304: Improper Neutralization of Special Elements used in an OS Command9.8 CriticalN/A1%Nov 5, 2025
CVE-2025-60753: Uncontrolled Resource Consumption5.5 MediumN/A0%Nov 5, 2025
CVE-2025-57130: Improper Access Control8.8 HighN/A0%Nov 5, 2025
CVE-2025-64459: Improper Neutralization of Special Elements used in an SQL Command9.1 CriticalN/A0%Nov 5, 2025
CVE-2025-64458: Inefficient Algorithmic Complexity7.5 HighN/A0%Nov 5, 2025
CVE-2025-61084: Improper Input Validation7.1 HighN/A0%Nov 5, 2025
CVE-2025-52602: Exposure of Private Personal Information to an Unauthorized Actor4.2 MediumN/A0%Nov 5, 2025
CVE-2025-47151: Access of Resource Using Incompatible Type9.8 CriticalN/A0%Nov 5, 2025
CVE-2025-46784: Missing Release of Memory after Effective Lifetime7.5 HighN/A0%Nov 5, 2025
CVE-2025-46705: Reachable Assertion7.5 HighN/A0%Nov 5, 2025
CVE-2025-46404: NULL Pointer Dereference7.5 HighN/A0%Nov 5, 2025
CVE-2025-3125: Unrestricted Upload of File with Dangerous Type6.7 MediumN/A0%Nov 5, 2025
CVE-2025-12497: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Nov 5, 2025
CVE-2025-11745: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6.4 MediumN/A0%Nov 5, 2025
CVE-2025-58337: Improper Access Control5.4 MediumN/A0%Nov 5, 2025
CVE-2025-12469: Missing Authorization4.3 MediumN/A0%Nov 5, 2025
CVE-2025-12468: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Nov 5, 2025
83051-83075 of 396830