The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-14591: Exposure of Sensitive Information to an Unauthorized Actor7.5 High5.3 Medium0%Dec 20, 2025
CVE-2025-14168: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 20, 2025
CVE-2025-14164: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 20, 2025
CVE-2025-13624: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 20, 2025
CVE-2025-13365: Cross-Site Request Forgery (CSRF)6.1 MediumN/A0%Dec 20, 2025
CVE-2025-13329: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A1%Dec 20, 2025
CVE-2025-12898: Missing Authorization5.3 MediumN/A0%Dec 20, 2025
CVE-2025-12581: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 20, 2025
CVE-2025-8065: Stack-based Buffer Overflow6.5 Medium8.7 High1%Dec 20, 2025
CVE-2025-14300: Missing Authentication for Critical Function8.1 High8.7 High0%Dec 20, 2025
CVE-2025-14299: Allocation of Resources Without Limits or Throttling6.5 Medium7.1 High0%Dec 20, 2025
CVE-2025-68613: Improper Control of Dynamically-Managed Code Resources9.9 CriticalN/A99%Dec 19, 2025
CVE-2025-68481: Improper Authorization5.9 MediumN/A0%Dec 19, 2025
CVE-2023-53959: Uncontrolled Search Path Element9.8 Critical8.5 High1%Dec 19, 2025
CVE-2023-53958: Weak Password Recovery Mechanism for Forgotten Password7.5 High8.6 High0%Dec 19, 2025
CVE-2023-53957: Sensitive Cookie with Improper SameSite Attribute8.8 High8.5 High1%Dec 19, 2025
CVE-2023-53956: Unrestricted Upload of File with Dangerous Type8.8 High8.7 High1%Dec 19, 2025
CVE-2023-53954: Unquoted Search Path or Element6.2 Medium8.5 High0%Dec 19, 2025
CVE-2023-53953: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 19, 2025
CVE-2023-53952: Unrestricted Upload of File with Dangerous Type8.8 High8.7 High1%Dec 19, 2025
CVE-2023-53951: Improper Verification of Cryptographic Signature9.8 Critical9.3 Critical0%Dec 19, 2025
CVE-2023-53948: Improper Neutralization of Special Elements used in an OS Command9.8 Critical9.3 Critical1%Dec 19, 2025
CVE-2023-53945: Improper Neutralization of Special Elements used in an OS Command8.8 High8.7 High1%Dec 19, 2025
CVE-2023-53950: Unrestricted Upload of File with Dangerous Type9.8 Critical9.3 Critical1%Dec 19, 2025
CVE-2023-53949: Incorrect Permission Assignment for Critical Resource8.4 High8.5 High0%Dec 19, 2025
79701-79725 of 592967