The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-36087: Use of Hard-coded Credentials8.1 HighN/A0%Oct 13, 2025
CVE-2025-11654: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Oct 13, 2025
CVE-2025-11653: Buffer Copy without Checking Size of Input8.8 High7.4 High0%Oct 13, 2025
CVE-2025-11652: Buffer Copy without Checking Size of Input8.8 High7.4 High0%Oct 13, 2025
CVE-2025-11651: Buffer Copy without Checking Size of Input8.8 High7.4 High0%Oct 13, 2025
CVE-2025-11650: Use of Weak Hash1.8 Low0.3 Low0%Oct 12, 2025
CVE-2025-11649: Use of Hard-coded Password7.0 High6.4 Medium0%Oct 12, 2025
CVE-2025-11648: Server-Side Request Forgery (SSRF)5.6 Medium2.9 Low0%Oct 12, 2025
CVE-2025-11647: Exposure of Sensitive Information to an Unauthorized Actor3.1 Low1.3 Low0%Oct 12, 2025
CVE-2025-11646: Improper Access Control6.3 Medium2.1 Low0%Oct 12, 2025
CVE-2025-11645: Insecure Storage of Sensitive Information2.4 Low0.9 Low0%Oct 12, 2025
CVE-2025-11644: Insecure Storage of Sensitive Information2.0 Low0.3 Low0%Oct 12, 2025
CVE-2025-11643: Use of Hard-coded Credentials3.7 Low6.3 Medium0%Oct 12, 2025
CVE-2025-11642: Improper Resource Shutdown or Release4.0 Medium4.1 Medium0%Oct 12, 2025
CVE-2025-11641: Improper Access Control3.9 Low1.0 Low0%Oct 12, 2025
CVE-2025-11640: Cleartext Transmission of Sensitive Information3.1 Low2.3 Low0%Oct 12, 2025
CVE-2025-11639: Insecure Storage of Sensitive Information3.3 Low4.8 Medium0%Oct 12, 2025
CVE-2025-11638: Improper Resource Shutdown or Release4.3 Medium5.3 Medium0%Oct 12, 2025
CVE-2025-11637: Concurrent Execution using Shared Resource with Improper Synchronization4.3 Medium5.3 Medium0%Oct 12, 2025
CVE-2025-11636: Server-Side Request Forgery (SSRF)5.6 Medium6.3 Medium0%Oct 12, 2025
CVE-2025-33096: Uncontrolled Recursion6.5 MediumN/A0%Oct 12, 2025
CVE-2025-2140: Origin Validation Error5.7 MediumN/A0%Oct 12, 2025
CVE-2025-2139: Client-Side Enforcement of Server-Side Security3.5 LowN/A0%Oct 12, 2025
CVE-2025-2138: Client-Side Enforcement of Server-Side Security3.5 LowN/A0%Oct 12, 2025
CVE-2025-11635: Uncontrolled Resource Consumption4.3 Medium5.3 Medium0%Oct 12, 2025
84726-84750 of 392630