The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-67869: Undefined Security WeaknessN/AN/AN/ADec 13, 2025
CVE-2025-67868: Undefined Security WeaknessN/AN/AN/ADec 13, 2025
CVE-2025-67867: Undefined Security WeaknessN/AN/AN/ADec 13, 2025
CVE-2025-67866: Undefined Security WeaknessN/AN/AN/ADec 13, 2025
CVE-2025-67865: Undefined Security WeaknessN/AN/AN/ADec 13, 2025
CVE-2025-67864: Undefined Security WeaknessN/AN/AN/ADec 13, 2025
CVE-2025-67863: Undefined Security WeaknessN/AN/AN/ADec 13, 2025
CVE-2025-36754: Authentication Bypass by SpoofingN/A9.3 Critical0%Dec 13, 2025
CVE-2025-36753: Authentication Bypass by Spoofing9.8 Critical8.6 High0%Dec 13, 2025
CVE-2025-36752: Use of Hard-coded Credentials9.8 Critical9.4 Critical0%Dec 13, 2025
CVE-2025-36751: Missing Encryption of Sensitive DataN/A9.4 Critical0%Dec 13, 2025
CVE-2025-36750: Improper Neutralization of Input During Web Page Generation5.4 Medium8.5 High0%Dec 13, 2025
CVE-2025-36748: Improper Neutralization of Input During Web Page Generation5.4 Medium8.4 High0%Dec 13, 2025
CVE-2025-36747: Use of Hard-coded Credentials9.8 Critical9.4 Critical0%Dec 13, 2025
CVE-2025-14620: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Dec 13, 2025
CVE-2025-14619: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium1%Dec 13, 2025
CVE-2025-14617: Improper Limitation of a Pathname to a Restricted Directory5.3 Medium1.9 Low0%Dec 13, 2025
CVE-2025-14607: Improper Restriction of Operations within the Bounds of a Memory Buffer6.3 Medium5.3 Medium0%Dec 13, 2025
CVE-2025-14606: Deserialization of Untrusted Data5.0 Medium1.3 Low0%Dec 13, 2025
CVE-2025-14590: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 13, 2025
CVE-2025-14589: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Dec 13, 2025
CVE-2025-14588: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 13, 2025
CVE-2025-14587: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 13, 2025
CVE-2025-14586: Improper Neutralization of Special Elements used in an OS Command9.8 Critical2.1 Low3%Dec 13, 2025
CVE-2025-14581: Missing Authorization4.3 MediumN/A0%Dec 13, 2025
80451-80475 of 552689