The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-63462: Stack-based Buffer Overflow7.5 HighN/A0%Oct 31, 2025
CVE-2025-63461: Stack-based Buffer Overflow7.5 HighN/A0%Oct 31, 2025
CVE-2025-63460: Stack-based Buffer Overflow7.5 HighN/A0%Oct 31, 2025
CVE-2025-59501: Authentication Bypass by Spoofing4.8 MediumN/A0%Oct 31, 2025
CVE-2025-63469: Stack-based Buffer Overflow7.5 HighN/A0%Oct 31, 2025
CVE-2025-63468: Stack-based Buffer Overflow7.5 HighN/A0%Oct 31, 2025
CVE-2025-63467: Stack-based Buffer Overflow7.5 HighN/A0%Oct 31, 2025
CVE-2025-63466: Stack-based Buffer Overflow7.5 HighN/A0%Oct 31, 2025
CVE-2025-29270: Exposure of Sensitive Information to an Unauthorized Actor10.0 CriticalN/A0%Oct 31, 2025
CVE-2025-12554: Protection Mechanism Failure9.8 Critical6.9 Medium0%Oct 31, 2025
CVE-2025-12553: Missing Validation of OpenSSL Certificate9.8 Critical10.0 Critical0%Oct 31, 2025
CVE-2025-12552: Weak Password Requirements9.8 Critical6.9 Medium0%Oct 31, 2025
CVE-2025-12509: Inclusion of Functionality from Untrusted Control Sphere8.4 HighN/A0%Oct 31, 2025
CVE-2025-12508: Cleartext Transmission of Sensitive Information8.4 HighN/A0%Oct 31, 2025
CVE-2025-12507: Unquoted Search Path or Element8.8 HighN/A0%Oct 31, 2025
CVE-2025-12357: Improper Restriction of Communication Channel to Intended Endpoints6.3 Medium5.3 Medium0%Oct 31, 2025
CVE-2025-64389: Cleartext Transmission of Sensitive InformationN/A8.3 High0%Oct 31, 2025
CVE-2025-64388: Uncontrolled Resource ConsumptionN/A9.2 Critical0%Oct 31, 2025
CVE-2025-64387: Improper Restriction of Rendered UI Layers or FramesN/A5.1 Medium0%Oct 31, 2025
CVE-2025-64385: Improper Input ValidationN/A9.2 Critical0%Oct 31, 2025
CVE-2025-64168: Concurrent Execution using Shared Resource with Improper Synchronization7.1 HighN/A0%Oct 31, 2025
CVE-2025-61427: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Oct 31, 2025
CVE-2025-60749: Uncontrolled Search Path Element7.8 HighN/A0%Oct 31, 2025
CVE-2025-57108: Use After Free9.8 CriticalN/A0%Oct 31, 2025
CVE-2025-57107: Heap-based Buffer Overflow7.1 HighN/A0%Oct 31, 2025
83126-83150 of 813908