The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-66493: Use After Free7.8 HighN/A0%Dec 19, 2025
CVE-2025-66174: Improper Authentication6.5 MediumN/A0%Dec 19, 2025
CVE-2025-66173: Improper Privilege Management6.2 MediumN/A0%Dec 19, 2025
CVE-2025-14449: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 19, 2025
CVE-2025-14267: Improper Removal of Sensitive Information Before Storage or Transfer4.9 Medium5.6 Medium0%Dec 19, 2025
CVE-2025-13999: Server-Side Request Forgery (SSRF)7.2 HighN/A0%Dec 19, 2025
CVE-2025-13754: Missing Authorization5.3 MediumN/A0%Dec 19, 2025
CVE-2025-13008: Exposure of Private Personal Information to an Unauthorized ActorN/A8.6 High0%Dec 19, 2025
CVE-2025-66498: Out-of-bounds Read5.3 MediumN/A0%Dec 19, 2025
CVE-2025-66497: Out-of-bounds Read5.3 MediumN/A0%Dec 19, 2025
CVE-2025-66496: Out-of-bounds Read5.3 MediumN/A0%Dec 19, 2025
CVE-2025-13307: Undefined Security Weakness7.2 HighN/A1%Dec 19, 2025
CVE-2025-14546: Improper Authorization6.3 Medium5.4 Medium0%Dec 19, 2025
CVE-2025-68491: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68490: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68489: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68488: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68487: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68486: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68485: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68484: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-68483: Undefined Security WeaknessN/AN/AN/ADec 19, 2025
CVE-2025-14940: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 19, 2025
CVE-2025-14939: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Dec 19, 2025
CVE-2025-67846: External Control of Assumed-Immutable Web Parameter4.9 MediumN/A0%Dec 19, 2025
79751-79775 of 592967