The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-68976: Missing Authorization5.4 MediumN/A0%Dec 30, 2025
CVE-2025-68975: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 30, 2025
CVE-2025-68974: Improper Control of Filename for Include/Require Statement in PHP Program6.6 MediumN/A0%Dec 30, 2025
CVE-2025-15245: Improper Limitation of a Pathname to a Restricted Directory3.3 Low2.0 Low1%Dec 30, 2025
CVE-2025-15244: Concurrent Execution using Shared Resource with Improper Synchronization3.7 Low2.9 Low0%Dec 30, 2025
CVE-2025-15359: Out-of-bounds Write9.8 CriticalN/A0%Dec 30, 2025
CVE-2025-15243: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical5.5 Medium0%Dec 30, 2025
CVE-2025-15242: Concurrent Execution using Shared Resource with Improper Synchronization3.1 Low1.3 Low0%Dec 30, 2025
CVE-2025-15358: Improper Input Validation7.5 HighN/A0%Dec 30, 2025
CVE-2025-15241: URL Redirection to Untrusted Site3.5 Low2.0 Low0%Dec 30, 2025
CVE-2025-15234: Heap-based Buffer Overflow8.8 High7.4 High3%Dec 30, 2025
CVE-2025-15103: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A0%Dec 30, 2025
CVE-2025-15102: Authentication Bypass Using an Alternate Path or Channel9.8 CriticalN/A0%Dec 30, 2025
CVE-2025-15355: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Dec 30, 2025
CVE-2025-15233: Heap-based Buffer Overflow8.8 High7.4 High1%Dec 30, 2025
CVE-2025-15232: Stack-based Buffer Overflow8.8 High7.4 High1%Dec 30, 2025
CVE-2025-15231: Stack-based Buffer Overflow8.8 High7.4 High1%Dec 30, 2025
CVE-2025-15230: Heap-based Buffer Overflow8.8 High7.4 High1%Dec 30, 2025
CVE-2025-15229: Improper Resource Shutdown or Release7.5 High5.5 Medium5%Dec 30, 2025
CVE-2025-15222: Deserialization of Untrusted Data5.0 Medium1.3 Low0%Dec 30, 2025
CVE-2025-14313: Undefined Security Weakness6.1 MediumN/A0%Dec 30, 2025
CVE-2025-14312: Undefined Security Weakness6.1 MediumN/A0%Dec 30, 2025
CVE-2025-15221: Improper Neutralization of Input During Web Page Generation5.4 Medium2.0 Low0%Dec 30, 2025
CVE-2025-15220: Improper Neutralization of Input During Web Page Generation6.1 Medium2.1 Low0%Dec 30, 2025
CVE-2025-15219: Improper Neutralization of Input During Web Page Generation5.4 Medium2.0 Low0%Dec 30, 2025
78976-79000 of 402816