The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-67730: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 12, 2025
CVE-2025-4970: Improper Neutralization of Input During Web Page Generation5.5 MediumN/A0%Dec 12, 2025
CVE-2025-14169: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Dec 12, 2025
CVE-2025-14049: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 12, 2025
CVE-2025-13891: Improper Limitation of a Pathname to a Restricted Directory6.5 MediumN/A0%Dec 12, 2025
CVE-2025-11876: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 12, 2025
CVE-2025-10583: Missing Authorization3.5 LowN/A0%Dec 12, 2025
CVE-2025-67737: Missing Authorization3.1 LowN/A0%Dec 12, 2025
CVE-2025-67728: Improper Neutralization of Special Elements used in a Command9.8 CriticalN/A0%Dec 12, 2025
CVE-2025-67727: Improper Control of Generation of Code9.8 Critical6.9 Medium0%Dec 12, 2025
CVE-2025-67726: Excessive Iteration7.5 HighN/A0%Dec 12, 2025
CVE-2025-14356: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 12, 2025
CVE-2025-14068: Improper Neutralization of Special Elements used in an SQL Command7.5 HighN/A0%Dec 12, 2025
CVE-2025-13660: Exposure of Sensitive Information to an Unauthorized Actor5.3 MediumN/A0%Dec 12, 2025
CVE-2025-12655: Missing Authorization5.3 MediumN/A0%Dec 12, 2025
CVE-2025-12570: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Dec 12, 2025
CVE-2025-67725: Uncontrolled Resource Consumption7.5 HighN/A0%Dec 12, 2025
CVE-2025-67724: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 12, 2025
CVE-2025-67508: Improper Neutralization of Special Elements used in a Command8.4 HighN/A0%Dec 12, 2025
CVE-2025-10684: Improper Authentication4.3 MediumN/A0%Dec 12, 2025
CVE-2025-66492: Improper Neutralization of Input During Web Page Generation8.2 HighN/A0%Dec 12, 2025
CVE-2025-66284: Improper Neutralization of Input During Web Page Generation5.4 Medium4.8 Medium0%Dec 12, 2025
CVE-2025-65120: Improper Neutralization of Input During Web Page Generation6.1 Medium5.1 Medium0%Dec 12, 2025
CVE-2025-64781: Initialization of a Resource with an Insecure Default4.7 Medium5.1 Medium0%Dec 12, 2025
CVE-2025-62192: Improper Neutralization of Special Elements used in an SQL Command5.4 Medium5.3 Medium0%Dec 12, 2025
80576-80600 of 744285