The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-12717: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 6, 2025
CVE-2025-12715: Improper Neutralization of Input During Web Page Generation6.4 MediumN/A0%Dec 6, 2025
CVE-2025-12673: Unrestricted Upload of File with Dangerous Type9.8 CriticalN/A0%Dec 6, 2025
CVE-2025-12577: Missing Authorization4.3 MediumN/A0%Dec 6, 2025
CVE-2025-12574: Missing Authorization4.3 MediumN/A0%Dec 6, 2025
CVE-2025-12091: Missing Authorization4.3 MediumN/A0%Dec 6, 2025
CVE-2025-13922: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Dec 6, 2025
CVE-2025-13292: Improper Privilege ManagementN/A7.6 High0%Dec 6, 2025
CVE-2025-12505: Improper Authorization5.4 MediumN/A0%Dec 6, 2025
CVE-2025-12510: Improper Neutralization of Input During Web Page Generation7.2 HighN/A0%Dec 6, 2025
CVE-2025-11263: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 6, 2025
CVE-2025-66629: Cross-Site Request Forgery (CSRF)3.7 LowN/A0%Dec 5, 2025
CVE-2025-34291: Origin Validation Error8.8 High9.4 Critical34%Dec 5, 2025
CVE-2025-14116: Server-Side Request Forgery (SSRF)4.7 Medium2.0 Low0%Dec 5, 2025
CVE-2025-14111: Improper Limitation of a Pathname to a Restricted Directory5.0 Medium1.3 Low0%Dec 5, 2025
CVE-2025-14108: Improper Neutralization of Special Elements used in a Command8.8 High7.4 High0%Dec 5, 2025
CVE-2025-14107: Improper Neutralization of Special Elements used in a Command8.8 High7.4 High1%Dec 5, 2025
CVE-2025-14106: Improper Neutralization of Special Elements used in a Command8.8 High7.4 High1%Dec 5, 2025
CVE-2025-13426: Improper Control of Dynamically-Managed Code ResourcesN/A8.7 High0%Dec 5, 2025
CVE-2025-8148: Incorrect Permission Assignment for Critical Resource4.2 MediumN/A0%Dec 5, 2025
CVE-2025-14105: Improper Resource Shutdown or Release4.3 Medium2.1 Low0%Dec 5, 2025
CVE-2025-66644: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A3%Dec 5, 2025
CVE-2025-66624: Out-of-bounds Read7.5 HighN/A0%Dec 5, 2025
CVE-2025-66623: Exposure of Sensitive Information to an Unauthorized Actor7.4 HighN/A0%Dec 5, 2025
CVE-2025-66581: Incorrect Authorization6.5 Medium1.3 Low0%Dec 5, 2025
81151-81175 of 731518