The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-58893: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58892: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58891: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58890: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58889: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58888: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58885: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58879: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58877: Missing Authorization7.5 HighN/A0%Dec 18, 2025
CVE-2025-58803: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-58710: Incorrect Privilege Assignment8.8 HighN/A0%Dec 18, 2025
CVE-2025-58709: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58708: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58706: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
CVE-2025-58225: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-57897: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Dec 18, 2025
CVE-2025-55707: Incorrect Privilege Assignment7.2 HighN/A0%Dec 18, 2025
CVE-2025-54751: Missing Authorization7.1 HighN/A0%Dec 18, 2025
CVE-2025-54748: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Dec 18, 2025
CVE-2025-54745: Missing Authorization6.5 MediumN/A0%Dec 18, 2025
CVE-2025-54743: Missing Authorization5.8 MediumN/A0%Dec 18, 2025
CVE-2025-54741: Missing Authorization6.5 MediumN/A0%Dec 18, 2025
CVE-2025-54723: Deserialization of Untrusted Data9.8 CriticalN/A0%Dec 18, 2025
CVE-2025-53453: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A1%Dec 18, 2025
CVE-2025-53449: Improper Control of Filename for Include/Require Statement in PHP Program8.1 HighN/A0%Dec 18, 2025
79926-79950 of 573046