The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-67527: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Dec 9, 2025
CVE-2025-67526: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Dec 9, 2025
CVE-2025-67525: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Dec 9, 2025
CVE-2025-67524: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Dec 9, 2025
CVE-2025-67523: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Dec 9, 2025
CVE-2025-67522: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Dec 9, 2025
CVE-2025-67521: Improper Control of Filename for Include/Require Statement in PHP Program7.5 HighN/A0%Dec 9, 2025
CVE-2025-67520: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Dec 9, 2025
CVE-2025-67519: Improper Neutralization of Special Elements used in an SQL Command7.6 HighN/A0%Dec 9, 2025
CVE-2025-67518: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Dec 9, 2025
CVE-2025-67517: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Dec 9, 2025
CVE-2025-67516: Improper Neutralization of Special Elements used in an SQL Command8.5 HighN/A0%Dec 9, 2025
CVE-2025-67515: Improper Control of Filename for Include/Require Statement in PHP Program8.8 HighN/A0%Dec 9, 2025
CVE-2025-67504: Insufficient Entropy9.1 CriticalN/A0%Dec 9, 2025
CVE-2025-67487: UNIX Symbolic Link (Symlink) Following8.6 High5.5 Medium0%Dec 9, 2025
CVE-2025-67474: Missing Authorization4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67473: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67472: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67471: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67470: Exposure of Sensitive System Information to an Unauthorized Control Sphere4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67469: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67468: Missing Authorization4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67467: Cross-Site Request Forgery (CSRF)5.4 MediumN/A0%Dec 9, 2025
CVE-2025-67466: Missing Authorization4.3 MediumN/A0%Dec 9, 2025
CVE-2025-67465: Cross-Site Request Forgery (CSRF)4.3 MediumN/A0%Dec 9, 2025
80901-80925 of 596487