The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-61976: Improper Check for Unusual or Exceptional Conditions7.5 High8.7 High0%Dec 16, 2025
CVE-2025-59479: Improper Restriction of Rendered UI Layers or Frames6.1 Medium5.1 Medium0%Dec 16, 2025
CVE-2025-13956: Missing Authorization5.3 MediumN/A1%Dec 16, 2025
CVE-2025-14777: Authentication Bypass by Alternate Name6.0 MediumN/A0%Dec 16, 2025
CVE-2025-62849: Improper Neutralization of Special Elements used in an SQL Command9.8 Critical5.2 Medium1%Dec 16, 2025
CVE-2025-62848: NULL Pointer Dereference7.5 High8.1 High1%Dec 16, 2025
CVE-2025-62847: Improper Neutralization of Argument Delimiters in a Command7.5 High6.6 Medium1%Dec 16, 2025
CVE-2025-59385: Authentication Bypass by Spoofing9.8 Critical8.1 High1%Dec 16, 2025
CVE-2025-14749: Improper Access Control6.3 Medium2.1 Low1%Dec 16, 2025
CVE-2025-14748: Improper Access Control5.4 Medium2.1 Low1%Dec 16, 2025
CVE-2025-14747: Improper Resource Shutdown or Release4.3 Medium2.1 Low1%Dec 16, 2025
CVE-2025-14746: Improper Authentication4.3 Medium2.1 Low1%Dec 16, 2025
CVE-2025-68115: Improper Neutralization of Input During Web Page Generation6.1 Medium5.3 Medium0%Dec 16, 2025
CVE-2025-68113: Misinterpretation of Input6.5 MediumN/A0%Dec 16, 2025
CVE-2025-67874: Observable Response Discrepancy6.5 Medium6.9 Medium0%Dec 16, 2025
CVE-2025-67751: Improper Neutralization of Special Elements used in an SQL Command7.2 HighN/A0%Dec 16, 2025
CVE-2025-67748: Incomplete List of Disallowed Inputs7.8 High7.1 High0%Dec 16, 2025
CVE-2025-67747: Incomplete List of Disallowed Inputs7.8 High7.1 High0%Dec 16, 2025
CVE-2025-67744: Improper Control of Generation of Code9.6 CriticalN/A1%Dec 16, 2025
CVE-2025-67736: Improper Neutralization of Special Elements used in an SQL Command7.2 High8.6 High6%Dec 16, 2025
CVE-2025-67735: Improper Neutralization of CRLF Sequences6.5 MediumN/A0%Dec 16, 2025
CVE-2025-67722: Untrusted Search Path7.8 High5.7 Medium0%Dec 16, 2025
CVE-2025-67715: Improper Access Control4.3 MediumN/A0%Dec 16, 2025
CVE-2025-67492: Improper Validation of Syntactic Correctness of Input5.3 MediumN/A0%Dec 16, 2025
CVE-2025-66449: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A1%Dec 16, 2025
80351-80375 of 582654