The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-15218: Buffer Copy without Checking Size of Input8.8 High7.4 High3%Dec 30, 2025
CVE-2025-15217: Buffer Copy without Checking Size of Input8.8 High7.4 High1%Dec 30, 2025
CVE-2025-15216: Stack-based Buffer Overflow8.8 High7.4 High1%Dec 30, 2025
CVE-2025-15215: Buffer Copy without Checking Size of Input8.8 High7.4 High1%Dec 30, 2025
CVE-2025-69235: Origin Validation Error7.5 HighN/A0%Dec 30, 2025
CVE-2025-69234: Improperly Implemented Security Check for Standard9.1 CriticalN/A0%Dec 30, 2025
CVE-2025-15214: Improper Neutralization of Input During Web Page Generation4.8 Medium1.9 Low0%Dec 30, 2025
CVE-2025-69217: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)7.7 HighN/A0%Dec 30, 2025
CVE-2025-15213: Improper Authorization4.3 Medium2.1 Low0%Dec 30, 2025
CVE-2025-15212: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical2.1 Low0%Dec 30, 2025
CVE-2025-15211: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical2.1 Low0%Dec 30, 2025
CVE-2025-68499: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Dec 30, 2025
CVE-2025-68498: Missing Authorization6.5 MediumN/A0%Dec 30, 2025
CVE-2025-68120: Undefined Security Weakness5.4 MediumN/A0%Dec 30, 2025
CVE-2025-68040: Insertion of Sensitive Information Into Sent Data6.5 MediumN/A0%Dec 30, 2025
CVE-2025-68036: Missing Authorization7.5 HighN/A0%Dec 30, 2025
CVE-2025-23554: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Dec 30, 2025
CVE-2025-23550: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Dec 30, 2025
CVE-2025-23469: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Dec 30, 2025
CVE-2025-23458: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Dec 30, 2025
CVE-2025-15210: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical2.1 Low0%Dec 30, 2025
CVE-2023-41656: Missing Authorization5.4 MediumN/A0%Dec 30, 2025
CVE-2023-32238: Improper Access Control5.4 MediumN/A0%Dec 30, 2025
CVE-2025-15284: Improper Input Validation3.7 Low6.3 Medium0%Dec 29, 2025
CVE-2025-15209: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical2.1 Low0%Dec 29, 2025
79001-79025 of 402816