The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-60058: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60057: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60056: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60055: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60054: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60053: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60052: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60051: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60050: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60049: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60048: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60047: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60046: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60045: Missing Authorization7.5 HighN/A0%Dec 18, 2025
CVE-2025-60044: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60043: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-60042: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-59134: Incorrect Privilege Assignment8.8 HighN/A0%Dec 18, 2025
CVE-2025-58951: Improper Neutralization of Special Elements used in an SQL Command9.3 CriticalN/A0%Dec 18, 2025
CVE-2025-58950: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58949: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58948: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58947: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58946: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58945: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
79876-79900 of 573046