The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-14900: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Dec 19, 2025
CVE-2025-14899: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Dec 19, 2025
CVE-2025-14733: Out-of-bounds Write9.8 Critical9.3 Critical27%Dec 19, 2025
CVE-2025-11774: Improper Neutralization of Special Elements used in an OS Command8.2 HighN/A1%Dec 19, 2025
CVE-2025-64675: Improper Neutralization of Input During Web Page Generation8.3 HighN/A1%Dec 19, 2025
CVE-2025-14898: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Dec 19, 2025
CVE-2025-14897: Improper Neutralization of Special Elements used in an SQL Command4.7 Medium2.0 Low0%Dec 19, 2025
CVE-2025-68422: Incorrect Authorization4.3 MediumN/A0%Dec 18, 2025
CVE-2025-68398: Improper Input Validation9.1 CriticalN/A1%Dec 18, 2025
CVE-2025-68390: Allocation of Resources Without Limits or Throttling4.9 MediumN/A0%Dec 18, 2025
CVE-2025-68389: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Dec 18, 2025
CVE-2025-68387: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 18, 2025
CVE-2025-68386: Incorrect Authorization4.3 MediumN/A0%Dec 18, 2025
CVE-2025-68385: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Dec 18, 2025
CVE-2025-68279: Improper Limitation of a Pathname to a Restricted Directory7.7 HighN/A0%Dec 18, 2025
CVE-2025-68388: Allocation of Resources Without Limits or Throttling5.3 MediumN/A0%Dec 18, 2025
CVE-2025-68384: Allocation of Resources Without Limits or Throttling6.5 MediumN/A0%Dec 18, 2025
CVE-2025-68383: Improper Validation of Specified Quantity in Input6.5 MediumN/A0%Dec 18, 2025
CVE-2025-68382: Out-of-bounds Read6.5 MediumN/A0%Dec 18, 2025
CVE-2025-68381: Out-of-bounds Write6.5 MediumN/A0%Dec 18, 2025
CVE-2025-65046: User Interface (UI) Misrepresentation of Critical Information3.1 LowN/A0%Dec 18, 2025
CVE-2025-65041: Improper Authorization10.0 CriticalN/A1%Dec 18, 2025
CVE-2025-65037: Improper Control of Generation of Code10.0 CriticalN/A1%Dec 18, 2025
CVE-2025-64677: Improper Neutralization of Input During Web Page Generation8.2 HighN/A1%Dec 18, 2025
CVE-2025-64676: Path Traversal: '.../...//'7.2 HighN/A1%Dec 18, 2025
79776-79800 of 403146