The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-14687: Client-Side Enforcement of Server-Side Security6.5 MediumN/A0%Dec 26, 2025
CVE-2025-13915: Authentication Bypass by Primary Weakness9.8 CriticalN/A9%Dec 26, 2025
CVE-2025-1721: Improper Clearing of Heap Memory Before Release7.5 HighN/A0%Dec 26, 2025
CVE-2025-12771: Improper Restriction of Operations within the Bounds of a Memory Buffer7.8 HighN/A0%Dec 26, 2025
CVE-2025-67450: Uncontrolled Search Path Element7.8 HighN/A0%Dec 26, 2025
CVE-2025-59888: Unquoted Search Path or Element6.7 MediumN/A0%Dec 26, 2025
CVE-2025-59887: Uncontrolled Search Path Element8.6 HighN/A0%Dec 26, 2025
CVE-2025-62578: Cleartext Transmission of Sensitive Information7.5 High7.2 High0%Dec 26, 2025
CVE-2025-8075: Improper Input Validation5.4 Medium5.8 Medium0%Dec 26, 2025
CVE-2025-68946: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 26, 2025
CVE-2025-52601: Use of Hard-coded Cryptographic Key7.8 High6.3 Medium0%Dec 26, 2025
CVE-2025-52600: Improper Input Validation7.2 High5.2 Medium0%Dec 26, 2025
CVE-2025-52599: Improper Privilege Management6.5 Medium6.3 Medium0%Dec 26, 2025
CVE-2025-52598: Improper Certificate Validation3.7 Low6.3 Medium0%Dec 26, 2025
CVE-2025-68945: Exposure of Private Personal Information to an Unauthorized Actor5.8 MediumN/A0%Dec 26, 2025
CVE-2025-68944: Unintended Proxy or Intermediary5.0 MediumN/A0%Dec 26, 2025
CVE-2025-68943: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.3 MediumN/A0%Dec 26, 2025
CVE-2025-15099: Improper Authentication9.8 Critical5.5 Medium1%Dec 26, 2025
CVE-2025-68942: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 26, 2025
CVE-2025-68941: Incorrect Authorization4.9 MediumN/A0%Dec 26, 2025
CVE-2025-68940: Incorrect Authorization3.1 LowN/A0%Dec 26, 2025
CVE-2025-68939: Improper Protection of Alternate Path8.2 HighN/A0%Dec 26, 2025
CVE-2025-15098: Server-Side Request Forgery (SSRF)6.3 Medium2.1 Low0%Dec 26, 2025
CVE-2025-15097: Improper Authentication7.3 High5.5 Medium1%Dec 26, 2025
CVE-2025-15095: Improper Neutralization of Input During Web Page Generation3.5 Low2.0 Low0%Dec 26, 2025
79201-79225 of 402816