The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-64367: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Oct 31, 2025
CVE-2025-64366: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Oct 31, 2025
CVE-2025-64365: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Oct 31, 2025
CVE-2025-64364: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Oct 31, 2025
CVE-2025-64363: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Oct 31, 2025
CVE-2025-64362: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Oct 31, 2025
CVE-2025-64361: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Oct 31, 2025
CVE-2025-64360: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Oct 31, 2025
CVE-2025-64359: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Oct 31, 2025
CVE-2025-64358: Missing Authorization4.3 MediumN/A0%Oct 31, 2025
CVE-2025-64357: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Oct 31, 2025
CVE-2025-64356: Missing Authorization4.3 MediumN/A0%Oct 31, 2025
CVE-2025-64354: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Oct 31, 2025
CVE-2025-64353: Deserialization of Untrusted Data8.8 HighN/A0%Oct 31, 2025
CVE-2025-64352: Missing Authorization2.7 LowN/A0%Oct 31, 2025
CVE-2025-64351: Insertion of Sensitive Information Into Sent Data4.3 MediumN/A0%Oct 31, 2025
CVE-2025-64350: Missing Authorization3.8 LowN/A0%Oct 31, 2025
CVE-2025-58149: Operation on a Resource after Expiration or Release7.5 HighN/A0%Oct 31, 2025
CVE-2025-58148: Out-of-bounds Read7.5 HighN/A0%Oct 31, 2025
CVE-2025-58147: Out-of-bounds Read7.5 HighN/A0%Oct 31, 2025
CVE-2025-40603: Insertion of Sensitive Information into Log File4.5 MediumN/A0%Oct 31, 2025
CVE-2025-11602: Sensitive Information in Resource Not Removed Before ReuseN/A6.3 Medium0%Oct 31, 2025
CVE-2025-12115: Client-Side Enforcement of Server-Side Security7.5 HighN/A0%Oct 31, 2025
CVE-2025-12041: Missing Authorization5.3 MediumN/A0%Oct 31, 2025
CVE-2025-11843: Authentication Bypass by SpoofingN/A8.8 High0%Oct 31, 2025
83151-83175 of 813908