The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-8082: Improper Neutralization of Input During Web Page Generation6.3 MediumN/A0%Dec 12, 2025
CVE-2025-14571: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 12, 2025
CVE-2025-14570: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 12, 2025
CVE-2025-14569: Use After Free5.3 Medium1.9 Low0%Dec 12, 2025
CVE-2025-14568: Improper Neutralization of Special Elements used in an SQL Command6.3 Medium2.1 Low0%Dec 12, 2025
CVE-2025-40345: Undefined Security WeaknessN/AN/A0%Dec 12, 2025
CVE-2025-67819: Improper Limitation of a Pathname to a Restricted Directory4.9 MediumN/A0%Dec 12, 2025
CVE-2025-67818: Improper Limitation of a Pathname to a Restricted Directory7.2 HighN/A0%Dec 12, 2025
CVE-2025-67342: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Dec 12, 2025
CVE-2025-64011: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 12, 2025
CVE-2023-29144: Integer Overflow or Wraparound3.3 LowN/A0%Dec 12, 2025
CVE-2025-67344: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Dec 12, 2025
CVE-2025-67341: Improper Neutralization of Input During Web Page Generation4.6 MediumN/A0%Dec 12, 2025
CVE-2025-66430: Improper Access Control9.1 CriticalN/A0%Dec 12, 2025
CVE-2025-65854: Improper Control of Generation of Code9.8 CriticalN/A0%Dec 12, 2025
CVE-2025-65530: Improper Neutralization of Directives in Dynamically Evaluated Code8.8 HighN/A0%Dec 12, 2025
CVE-2025-53960: Use of a Cryptographic Primitive with a Risky Implementation5.9 MediumN/A0%Dec 12, 2025
CVE-2025-14567: Missing Authentication for Critical Function5.3 Medium5.5 Medium0%Dec 12, 2025
CVE-2025-14566: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 12, 2025
CVE-2025-14565: Improper Neutralization of Special Elements used in an SQL Command7.3 High5.5 Medium0%Dec 12, 2025
CVE-2025-13733: Incorrect Permission Assignment for Critical Resource7.8 High8.5 High0%Dec 12, 2025
CVE-2025-12843: Improper Control of Generation of Code5.5 Medium6.9 Medium0%Dec 12, 2025
CVE-2025-58770: Improper Handling of Insufficient Permissions or Privileges8.8 High7.2 High0%Dec 12, 2025
CVE-2025-54981: Use of a Broken or Risky Cryptographic Algorithm7.5 HighN/A0%Dec 12, 2025
CVE-2025-54947: Use of Hard-coded Cryptographic Key9.8 CriticalN/A0%Dec 12, 2025
80551-80575 of 744285