The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-13642: Improper Control of Generation of Code5.4 MediumN/A0%Dec 9, 2025
CVE-2025-13604: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Dec 9, 2025
CVE-2025-13428: Improper Input Validation7.2 High8.6 High0%Dec 9, 2025
CVE-2025-13071: Improper Neutralization of Input During Web Page Generation7.1 HighN/A0%Dec 9, 2025
CVE-2025-13070: Improper Limitation of a Pathname to a Restricted Directory6.6 MediumN/A0%Dec 9, 2025
CVE-2025-13031: Undefined Security Weakness5.9 MediumN/A0%Dec 9, 2025
CVE-2025-12807: Improper Neutralization of Special Elements used in an SQL CommandN/A8.7 High0%Dec 9, 2025
CVE-2025-12705: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Dec 9, 2025
CVE-2025-12558: Exposure of Sensitive Information to an Unauthorized Actor4.3 MediumN/A0%Dec 9, 2025
CVE-2025-12504: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Dec 9, 2025
CVE-2025-12381: Improper Privilege Management7.8 High6.1 Medium0%Dec 9, 2025
CVE-2025-11022: Cross-Site Request Forgery (CSRF)9.6 CriticalN/A0%Dec 9, 2025
CVE-2025-10876: Improper Neutralization of Input During Web Page Generation5.3 MediumN/A0%Dec 9, 2025
CVE-2025-10655: Improper Neutralization of Special Elements used in an SQL Command8.8 High8.6 High0%Dec 9, 2025
CVE-2025-10573: Improper Neutralization of Input During Web Page Generation9.6 CriticalN/A0%Dec 9, 2025
CVE-2024-56840: Improper Neutralization of Special Elements in Output Used by a Downstream Component7.2 High7.5 High0%Dec 9, 2025
CVE-2024-56839: Improper Neutralization of Special Elements in Output Used by a Downstream Component7.2 High8.6 High0%Dec 9, 2025
CVE-2024-56838: Improper Neutralization of Special Elements in Output Used by a Downstream Component7.2 High8.6 High0%Dec 9, 2025
CVE-2024-56837: Improper Neutralization of Special Elements used in a Command7.2 High8.6 High0%Dec 9, 2025
CVE-2024-56836: Improper Neutralization of Special Elements used in a Command7.5 High7.7 High0%Dec 9, 2025
CVE-2024-56835: Improper Neutralization of Special Elements in Output Used by a Downstream Component8.8 High8.7 High0%Dec 9, 2025
CVE-2024-56464: Exposure of Information Through Directory Listing2.7 LowN/A0%Dec 9, 2025
CVE-2024-38798: Exposure of Sensitive Information to an Unauthorized ActorN/A5.8 Medium0%Dec 9, 2025
CVE-2023-53857: Undefined Security WeaknessN/AN/A0%Dec 9, 2025
CVE-2023-53851: Undefined Security Weakness8.4 HighN/A0%Dec 9, 2025
81026-81050 of 731518