The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2023-53974: Missing Authentication for Critical Function7.5 High8.8 High1%Dec 22, 2025
CVE-2021-47715: Server-Side Request Forgery (SSRF)5.3 Medium6.9 Medium0%Dec 22, 2025
CVE-2025-66736: Improper Access Control7.1 HighN/A0%Dec 22, 2025
CVE-2025-66735: Improper Access Control7.5 HighN/A0%Dec 22, 2025
CVE-2025-65817: Improper Control of Generation of Code8.8 HighN/A0%Dec 22, 2025
CVE-2025-67418: Use of Hard-coded Credentials9.8 CriticalN/A1%Dec 22, 2025
CVE-2025-67291: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 22, 2025
CVE-2025-67290: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 22, 2025
CVE-2025-65837: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 22, 2025
CVE-2025-65790: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 22, 2025
CVE-2024-27708: Improper Neutralization of Special Elements in Output Used by a Downstream Component9.6 CriticalN/A1%Dec 22, 2025
CVE-2024-25812: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 22, 2025
CVE-2025-67288: Unrestricted Upload of File with Dangerous Type10.0 CriticalN/A1%Dec 22, 2025
CVE-2025-63664: Improper Access Control7.5 HighN/A0%Dec 22, 2025
CVE-2025-63663: Improper Access Control7.5 HighN/A0%Dec 22, 2025
CVE-2025-63662: Exposure of Sensitive Information to an Unauthorized Actor7.5 HighN/A0%Dec 22, 2025
CVE-2025-26787: External Control of Critical State Data4.7 MediumN/A0%Dec 22, 2025
CVE-2025-15033: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Dec 22, 2025
CVE-2024-35321: Improper Neutralization of Input During Web Page Generation4.3 MediumN/A0%Dec 22, 2025
CVE-2024-25814: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 22, 2025
CVE-2025-68645: Improper Control of Filename for Include/Require Statement in PHP Program8.8 HighN/A49%Dec 22, 2025
CVE-2025-67289: Improper Neutralization of Input During Web Page Generation9.6 CriticalN/A0%Dec 22, 2025
CVE-2025-65270: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 22, 2025
CVE-2025-67443: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 22, 2025
CVE-2025-10021: Use of Uninitialized VariableN/A7.0 High0%Dec 22, 2025
79651-79675 of 396266