The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-68326: Undefined Security WeaknessN/AN/A0%Dec 22, 2025
CVE-2025-67826: Improper Privilege Management7.7 HighN/A0%Dec 22, 2025
CVE-2025-61740: Origin Validation ErrorN/A7.2 High0%Dec 22, 2025
CVE-2025-26379: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)N/A7.2 High0%Dec 22, 2025
CVE-2025-14018: Unquoted Search Path or Element7.3 HighN/A0%Dec 22, 2025
CVE-2025-14273: Incorrect Implementation of Authentication Algorithm7.2 HighN/A0%Dec 22, 2025
CVE-2025-8460: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Dec 22, 2025
CVE-2025-61739: Reusing a Nonce, Key Pair in EncryptionN/A7.2 High0%Dec 22, 2025
CVE-2025-61738: Cleartext Transmission of Sensitive InformationN/A2.3 Low0%Dec 22, 2025
CVE-2025-54890: Improper Neutralization of Input During Web Page Generation6.8 MediumN/A0%Dec 22, 2025
CVE-2025-12514: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Dec 22, 2025
CVE-2025-62880: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 22, 2025
CVE-2025-62107: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 22, 2025
CVE-2025-62094: Improper Neutralization of Input During Web Page Generation6.5 MediumN/A0%Dec 22, 2025
CVE-2025-8305: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Dec 22, 2025
CVE-2025-8304: Exposure of Sensitive Information to an Unauthorized Actor6.5 MediumN/A0%Dec 22, 2025
CVE-2025-11545: Exposure of Sensitive System Information to an Unauthorized Control SphereN/A9.5 Critical0%Dec 22, 2025
CVE-2025-11544: Hidden FunctionalityN/A9.5 Critical0%Dec 22, 2025
CVE-2025-15014: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium5.3 Medium0%Dec 22, 2025
CVE-2025-15013: Stack-based Buffer Overflow5.3 Medium1.9 Low0%Dec 22, 2025
CVE-2025-15012: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical5.5 Medium0%Dec 22, 2025
CVE-2025-12049: Missing Authentication for Critical Function9.8 Critical9.2 Critical0%Dec 22, 2025
CVE-2025-11543: Improper Validation of Integrity Check Value9.8 Critical9.5 Critical0%Dec 22, 2025
CVE-2025-11542: Stack-based Buffer Overflow9.8 Critical8.4 High0%Dec 22, 2025
CVE-2025-11541: Stack-based Buffer Overflow9.8 Critical9.2 Critical0%Dec 22, 2025
79676-79700 of 592967