The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2023-36337: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 15, 2025
CVE-2025-66440: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Dec 15, 2025
CVE-2025-66439: Improper Neutralization of Special Elements used in an SQL Command8.8 HighN/A0%Dec 15, 2025
CVE-2025-66438: Improper Neutralization of Special Elements Used in a Template Engine8.8 HighN/A1%Dec 15, 2025
CVE-2025-66437: Improper Neutralization of Special Elements Used in a Template Engine8.8 HighN/A1%Dec 15, 2025
CVE-2025-66436: Improper Control of Generation of Code4.3 MediumN/A0%Dec 15, 2025
CVE-2025-14038: Missing Authorization7.0 HighN/A0%Dec 15, 2025
CVE-2025-66435: Improper Control of Generation of Code4.3 MediumN/A0%Dec 15, 2025
CVE-2025-66434: Improper Control of Generation of Code8.8 HighN/A1%Dec 15, 2025
CVE-2025-65742: Missing Authorization8.2 HighN/A0%Dec 15, 2025
CVE-2025-55901: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A1%Dec 15, 2025
CVE-2025-55893: Improper Neutralization of Special Elements used in a Command6.5 MediumN/A1%Dec 15, 2025
CVE-2025-11393: Unintended Proxy or Intermediary8.7 HighN/A0%Dec 15, 2025
CVE-2025-66963: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Dec 15, 2025
CVE-2025-66844: Server-Side Request Forgery (SSRF)9.1 CriticalN/A0%Dec 15, 2025
CVE-2025-66843: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 15, 2025
CVE-2025-60786: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A1%Dec 15, 2025
CVE-2025-14387: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 15, 2025
CVE-2025-13888: Incorrect Privilege Assignment9.1 CriticalN/A1%Dec 15, 2025
CVE-2025-13824: Release of Invalid Pointer or ReferenceN/A8.7 High0%Dec 15, 2025
CVE-2025-13823: Dependency on Vulnerable Third-Party ComponentN/A7.1 High0%Dec 15, 2025
CVE-2024-44599: Unrestricted Upload of File with Dangerous Type8.3 HighN/A0%Dec 15, 2025
CVE-2024-44598: Unrestricted Upload of File with Dangerous Type8.8 HighN/A0%Dec 15, 2025
CVE-2025-34412: Undefined Security WeaknessN/A6.9 Medium0%Dec 15, 2025
CVE-2025-34411: Undefined Security WeaknessN/A6.9 Medium0%Dec 15, 2025
80376-80400 of 582654