The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-67876: Improper Neutralization of Input During Web Page Generation5.4 Medium9.3 Critical0%Dec 17, 2025
CVE-2025-67875: Improper Neutralization of Input During Web Page Generation5.4 Medium8.5 High0%Dec 17, 2025
CVE-2025-67873: Heap-based Buffer Overflow4.8 MediumN/A0%Dec 17, 2025
CVE-2025-67794: Incorrect Permission Assignment for Critical Resource6.1 MediumN/A0%Dec 17, 2025
CVE-2025-67791: Improper Authentication9.8 CriticalN/A0%Dec 17, 2025
CVE-2025-14832: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 17, 2025
CVE-2025-67793: Improper Privilege Management9.8 CriticalN/A0%Dec 17, 2025
CVE-2025-67792: Improper Privilege Management7.8 HighN/A0%Dec 17, 2025
CVE-2025-67790: Improper Null Termination7.5 HighN/A0%Dec 17, 2025
CVE-2025-67789: Improper Access Control5.3 MediumN/A0%Dec 17, 2025
CVE-2025-66647: Buffer Copy without Checking Size of Input9.8 Critical1.7 Low1%Dec 17, 2025
CVE-2025-59849: Improper Restriction of Rendered UI Layers or Frames6.1 MediumN/A0%Dec 17, 2025
CVE-2025-55254: URL Redirection to Untrusted Site3.7 LowN/A0%Dec 17, 2025
CVE-2025-53000: Uncontrolled Search Path Element7.8 High8.5 High0%Dec 17, 2025
CVE-2025-46292: Improper Access Control5.5 MediumN/A0%Dec 17, 2025
CVE-2025-46291: Protection Mechanism Failure7.8 HighN/A0%Dec 17, 2025
CVE-2025-46288: Improper Access Control5.5 MediumN/A0%Dec 17, 2025
CVE-2025-46283: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Dec 17, 2025
CVE-2025-46282: Improper Access Control5.5 MediumN/A0%Dec 17, 2025
CVE-2025-46281: Protection Mechanism Failure8.8 HighN/A0%Dec 17, 2025
CVE-2025-46279: Exposure of Sensitive Information to an Unauthorized Actor3.3 LowN/A0%Dec 17, 2025
CVE-2025-46278: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Dec 17, 2025
CVE-2025-46277: Insertion of Sensitive Information into Log File3.3 LowN/A0%Dec 17, 2025
CVE-2025-43541: Access of Resource Using Incompatible Type4.3 MediumN/A0%Dec 17, 2025
CVE-2025-43536: Use After Free4.3 MediumN/A0%Dec 17, 2025
80026-80050 of 598912