The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-66566: Insertion of Sensitive Information Into Sent DataN/A8.2 High0%Dec 5, 2025
CVE-2025-66562: Improper Neutralization of Input During Web Page Generation9.6 Critical8.9 High0%Dec 5, 2025
CVE-2025-66558: Authorization Bypass Through User-Controlled Key3.1 LowN/A0%Dec 5, 2025
CVE-2025-66557: Improper Access Control4.3 MediumN/A0%Dec 5, 2025
CVE-2025-66556: Authorization Bypass Through User-Controlled Key3.5 LowN/A0%Dec 5, 2025
CVE-2025-66554: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Dec 5, 2025
CVE-2025-66553: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 5, 2025
CVE-2025-66551: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 5, 2025
CVE-2025-66549: Generation of Error Message Containing Sensitive Information2.4 LowN/A0%Dec 5, 2025
CVE-2025-66548: Improper Encoding or Escaping of Output3.3 LowN/A0%Dec 5, 2025
CVE-2025-66545: Improper Neutralization3.5 LowN/A0%Dec 5, 2025
CVE-2025-66515: Improper Authentication2.7 LowN/A0%Dec 5, 2025
CVE-2025-66514: Improper Neutralization of Input During Web Page Generation3.5 LowN/A0%Dec 5, 2025
CVE-2025-66513: Authorization Bypass Through User-Controlled Key4.3 MediumN/A0%Dec 5, 2025
CVE-2025-34257: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 5, 2025
CVE-2025-34256: Use of Hard-coded Cryptographic Key9.8 Critical10.0 Critical0%Dec 5, 2025
CVE-2020-36882: Unrestricted Upload of File with Dangerous Type7.5 High8.7 High0%Dec 5, 2025
CVE-2020-36881: Improper Restriction of Operations within the Bounds of a Memory Buffer7.8 High8.6 High0%Dec 5, 2025
CVE-2020-36880: Improper Restriction of Operations within the Bounds of a Memory Buffer7.8 High8.6 High0%Dec 5, 2025
CVE-2020-36879: Unquoted Search Path or ElementN/A8.5 High0%Dec 5, 2025
CVE-2020-36878: External Control of File Name or PathN/A8.7 High0%Dec 5, 2025
CVE-2020-36877: Improper Neutralization of Special Elements used in an OS CommandN/A9.3 Critical1%Dec 5, 2025
CVE-2025-34265: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 5, 2025
CVE-2025-34263: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 5, 2025
CVE-2025-34266: Improper Neutralization of Input During Web Page Generation5.4 Medium5.1 Medium0%Dec 5, 2025
81176-81200 of 586773