The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-66208: Improper Neutralization of Special Elements used in an OS Command9.8 Critical7.2 High1%Dec 3, 2025
CVE-2025-66032: Improper Neutralization of Special Elements used in a Command9.8 Critical8.7 High0%Dec 3, 2025
CVE-2025-63402: Allocation of Resources Without Limits or Throttling5.5 MediumN/A0%Dec 3, 2025
CVE-2025-63401: Improper Neutralization of Input During Web Page Generation5.5 MediumN/A0%Dec 3, 2025
CVE-2025-50360: Heap-based Buffer Overflow8.4 HighN/A0%Dec 3, 2025
CVE-2025-33211: Improper Validation of Specified Quantity in Input7.5 HighN/A0%Dec 3, 2025
CVE-2025-33208: Uncontrolled Search Path Element8.8 HighN/A0%Dec 3, 2025
CVE-2025-33201: Improper Check for Unusual or Exceptional Conditions7.5 HighN/A0%Dec 3, 2025
CVE-2025-13992: Improper Protection of Physical Side Channels4.7 MediumN/A0%Dec 3, 2025
CVE-2025-12819: Untrusted Search Path7.5 HighN/A0%Dec 3, 2025
CVE-2025-12084: Inefficient Algorithmic Complexity5.3 Medium6.3 Medium0%Dec 3, 2025
CVE-2024-3884: Improper Input Validation7.5 HighN/A1%Dec 3, 2025
CVE-2025-66478: Undefined Security WeaknessN/AN/AN/ADec 3, 2025
CVE-2025-64763: Protection Mechanism Failure3.7 LowN/A0%Dec 3, 2025
CVE-2025-64527: NULL Pointer Dereference6.5 MediumN/A0%Dec 3, 2025
CVE-2025-64443: Exposed Dangerous Method or Function9.6 Critical7.3 High0%Dec 3, 2025
CVE-2025-66431: UNIX Symbolic Link (Symlink) Following7.8 HighN/A0%Dec 3, 2025
CVE-2025-65843: Improper Link Resolution Before File Access7.7 HighN/A0%Dec 3, 2025
CVE-2025-65842: Incorrect Privilege Assignment5.1 MediumN/A0%Dec 3, 2025
CVE-2025-65841: Improper Access Control6.2 MediumN/A0%Dec 3, 2025
CVE-2025-62686: Improper Privilege Management6.2 MediumN/A0%Dec 3, 2025
CVE-2025-55076: Improper Privilege Management6.2 MediumN/A0%Dec 3, 2025
CVE-2025-54326: NULL Pointer Dereference7.5 HighN/A0%Dec 3, 2025
CVE-2025-54065: Improper Control of Dynamically-Managed Code Resources7.9 HighN/A0%Dec 3, 2025
CVE-2025-53965: Improper Restriction of Operations within the Bounds of a Memory Buffer5.3 MediumN/A0%Dec 3, 2025
81301-81325 of 575892