The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-12077: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 13, 2025
CVE-2025-12076: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 13, 2025
CVE-2025-11970: Server-Side Request Forgery (SSRF)4.4 MediumN/A0%Dec 13, 2025
CVE-2025-11707: Use of Insufficiently Random Values5.3 MediumN/A0%Dec 13, 2025
CVE-2025-11693: Exposure of Sensitive Information to an Unauthorized Actor9.8 CriticalN/A2%Dec 13, 2025
CVE-2025-11376: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 13, 2025
CVE-2025-11164: Missing Authorization4.3 MediumN/A0%Dec 13, 2025
CVE-2025-10738: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Dec 13, 2025
CVE-2025-10289: Improper Neutralization of Special Elements used in an SQL Command5.9 MediumN/A0%Dec 13, 2025
CVE-2025-0969: Exposure of Private Personal Information to an Unauthorized Actor6.5 MediumN/A0%Dec 13, 2025
CVE-2025-13970: Cross-Site Request Forgery (CSRF)8.0 High7.0 High0%Dec 13, 2025
CVE-2025-67749: Out-of-bounds ReadN/A5.3 Medium0%Dec 12, 2025
CVE-2025-67721: Insertion of Sensitive Information Into Sent Data7.5 High6.3 Medium1%Dec 12, 2025
CVE-2025-14585: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 12, 2025
CVE-2025-14584: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 12, 2025
CVE-2025-14066: Undefined Security WeaknessN/AN/AN/ADec 12, 2025
CVE-2025-54369: Improper Neutralization of Alternate XSS SyntaxN/A9.3 Critical1%Dec 12, 2025
CVE-2025-14583: Unrestricted Upload of File with Dangerous Type7.3 High5.5 Medium0%Dec 12, 2025
CVE-2025-14582: Unrestricted Upload of File with Dangerous Type4.7 Medium2.0 Low0%Dec 12, 2025
CVE-2025-67750: Improper Control of Generation of Code8.4 HighN/A0%Dec 12, 2025
CVE-2025-67634: Improper Neutralization of Input During Web Page Generation4.4 Medium4.6 Medium0%Dec 12, 2025
CVE-2025-46289: Improper Authorization5.5 MediumN/A0%Dec 12, 2025
CVE-2025-46287: User Interface (UI) Misrepresentation of Critical Information6.5 MediumN/A0%Dec 12, 2025
CVE-2025-46285: Integer Overflow or Wraparound7.8 HighN/A0%Dec 12, 2025
CVE-2025-46276: Undefined Security Weakness5.5 MediumN/A0%Dec 12, 2025
80501-80525 of 552689