The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2019-25269: Unquoted Search Path or Element7.8 High8.5 High0%Feb 5, 2026
CVE-2026-20730: Exposure of Sensitive Information to an Unauthorized Actor3.3 Low2.0 Low0%Feb 4, 2026
CVE-2025-14740: Incorrect Permission Assignment for Critical Resource6.7 MediumN/A0%Feb 4, 2026
CVE-2025-60865: Improper Access Control7.8 HighN/A0%Feb 3, 2026
CVE-2019-25261: Unquoted Search Path or Element7.8 High8.5 High0%Feb 3, 2026
CVE-2026-25228: Improper Limitation of a Pathname to a Restricted Directory5.0 MediumN/A0%Feb 2, 2026
CVE-2026-1232: Protection Mechanism FailureN/A6.8 Medium0%Feb 2, 2026
CVE-2020-37047: Unquoted Search Path or Element7.8 High8.5 High0%Feb 1, 2026
CVE-2020-37044: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Jan 30, 2026
CVE-2020-37041: Improper Limitation of a Pathname to a Restricted Directory7.5 High7.1 High1%Jan 30, 2026
CVE-2020-37025: Buffer Copy without Checking Size of Input8.4 High8.4 High0%Jan 30, 2026
CVE-2025-36442: Improper Neutralization of Special Elements in Data Query Logic6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36428: Improper Validation of Specified Quantity in Input5.3 MediumN/A0%Jan 30, 2026
CVE-2025-36427: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36424: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36423: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36387: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36366: Improper Neutralization of Special Elements in Data Query Logic6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36365: Authorization Bypass Through User-Controlled Key6.8 MediumN/A0%Jan 30, 2026
CVE-2025-36353: Improper Neutralization of Special Elements in Data Query Logic6.2 MediumN/A0%Jan 30, 2026
CVE-2025-36184: Execution with Unnecessary Privileges7.2 HighN/A1%Jan 30, 2026
CVE-2025-36123: Allocation of Resources Without Limits or Throttling6.2 MediumN/A0%Jan 30, 2026
CVE-2025-36098: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36070: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Jan 30, 2026
CVE-2025-36009: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Jan 30, 2026
2551-2575 of 16013