The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-40539: Incorrect Type Conversion or Cast9.1 CriticalN/A0%Feb 24, 2026
CVE-2025-40538: Improper Privilege Management9.1 CriticalN/A1%Feb 24, 2026
CVE-2025-63946: Improper Link Resolution Before File Access7.4 HighN/A0%Feb 23, 2026
CVE-2025-63945: Improper Link Resolution Before File Access7.4 HighN/A0%Feb 23, 2026
CVE-2026-27212: Improperly Controlled Modification of Object Prototype Attributes7.8 High9.4 Critical0%Feb 21, 2026
CVE-2026-27199: Improper Handling of Windows Device Names5.3 Medium6.3 Medium1%Feb 21, 2026
CVE-2026-2490: Improper Link Resolution Before File Access5.5 MediumN/A0%Feb 20, 2026
CVE-2026-27115: Improper Limitation of a Pathname to a Restricted Directory7.1 HighN/A0%Feb 20, 2026
CVE-2026-2818: Relative Path Traversal8.2 HighN/A0%Feb 20, 2026
CVE-2026-25926: Untrusted Search Path7.3 HighN/A0%Feb 19, 2026
CVE-2019-25365: Stack-based Buffer Overflow9.8 Critical8.4 High0%Feb 18, 2026
CVE-2019-25357: Stack-based Buffer Overflow8.4 High8.4 High0%Feb 18, 2026
CVE-2019-25352: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High1%Feb 18, 2026
CVE-2026-2464: Improper Limitation of a Pathname to a Restricted DirectoryN/A8.7 High1%Feb 18, 2026
CVE-2026-26119: Improper Authentication8.8 HighN/A1%Feb 17, 2026
CVE-2025-33130: Buffer Copy without Checking Size of Input6.5 MediumN/A0%Feb 17, 2026
CVE-2025-33124: Incorrect Calculation of Buffer Size6.5 MediumN/A0%Feb 17, 2026
CVE-2025-27904: Cross-Site Request Forgery (CSRF)6.5 MediumN/A0%Feb 17, 2026
CVE-2025-27903: Cleartext Transmission of Sensitive Information5.9 MediumN/A0%Feb 17, 2026
CVE-2025-27901: Improper Neutralization of HTTP Headers for Scripting Syntax6.5 MediumN/A0%Feb 17, 2026
CVE-2025-13108: Sensitive Information in Resource Not Removed Before Reuse5.5 MediumN/A0%Feb 17, 2026
CVE-2025-36425: Plaintext Storage of a Password5.3 MediumN/A0%Feb 17, 2026
CVE-2025-36247: Improper Restriction of XML External Entity Reference7.1 HighN/A0%Feb 17, 2026
CVE-2025-14689: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Feb 17, 2026
CVE-2025-13867: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Feb 17, 2026
2476-2500 of 16013