The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-43509: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43506: Access of Resource Using Incompatible Type7.5 HighN/A0%Dec 12, 2025
CVE-2025-43497: Missing Authorization5.2 MediumN/A0%Dec 12, 2025
CVE-2025-43494: Improper Input Validation7.5 HighN/A1%Dec 12, 2025
CVE-2025-43482: Improper Input Validation5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43473: Exposure of Sensitive Information to an Unauthorized Actor5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43471: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43470: Incorrect Permission Assignment for Critical Resource5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43467: Undefined Security Weakness7.8 HighN/A0%Dec 12, 2025
CVE-2025-43466: Improper Neutralization of Directives in Dynamically Evaluated Code5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43465: Improper Limitation of a Pathname to a Restricted Directory5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43464: Improper Input Validation6.5 MediumN/A0%Dec 12, 2025
CVE-2025-43463: Improper Limitation of a Pathname to a Restricted Directory5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43461: Improper Link Resolution Before File Access5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43437: Exposure of Sensitive Information to an Unauthorized Actor3.3 LowN/A0%Dec 12, 2025
CVE-2025-43416: Improper Access Control5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43410: Use of Cache Containing Sensitive Information2.4 LowN/A0%Dec 12, 2025
CVE-2025-43406: Exposure of Sensitive System Information to an Unauthorized Control Sphere5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43404: Improper Access Control3.3 LowN/A0%Dec 12, 2025
CVE-2025-43402: Out-of-bounds Write7.8 HighN/A0%Dec 12, 2025
CVE-2025-43393: Improper Access Control5.2 MediumN/A0%Dec 12, 2025
CVE-2025-43388: Improper Neutralization of Directives in Dynamically Evaluated Code5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43381: Improper Link Resolution Before File Access5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43351: Improper Access Control5.5 MediumN/A0%Dec 12, 2025
CVE-2025-43320: Improper Privilege Management7.8 HighN/A0%Dec 12, 2025
80526-80550 of 404283