The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-65215: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 2, 2025
CVE-2025-65105: UNIX Symbolic Link (Symlink) Following4.5 MediumN/A0%Dec 2, 2025
CVE-2025-64750: UNIX Symbolic Link (Symlink) Following4.5 MediumN/A0%Dec 2, 2025
CVE-2025-60854: Improper Neutralization of Special Elements used in a Command9.8 CriticalN/A0%Dec 2, 2025
CVE-2025-58386: Improper Authorization9.8 CriticalN/A0%Dec 2, 2025
CVE-2025-52622: Initialization of a Resource with an Insecure Default5.4 MediumN/A0%Dec 2, 2025
CVE-2025-65656: Improper Control of Filename for Include/Require Statement in PHP Program9.8 CriticalN/A0%Dec 2, 2025
CVE-2025-65358: Improper Neutralization of Special Elements used in an SQL Command9.8 CriticalN/A0%Dec 2, 2025
CVE-2025-65186: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 2, 2025
CVE-2025-64070: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Dec 2, 2025
CVE-2025-13828: Missing AuthorizationN/A9.0 Critical0%Dec 2, 2025
CVE-2025-13827: Unrestricted Upload of File with Dangerous TypeN/A8.8 High0%Dec 2, 2025
CVE-2025-65187: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 2, 2025
CVE-2025-64460: Inefficient Algorithmic Complexity7.5 HighN/A0%Dec 2, 2025
CVE-2025-63872: Improper Neutralization of Input During Web Page Generation6.1 MediumN/A0%Dec 2, 2025
CVE-2025-59704: Improper Authentication4.6 MediumN/A0%Dec 2, 2025
CVE-2025-59703: Improper Access Control9.1 CriticalN/A0%Dec 2, 2025
CVE-2025-58113: Out-of-bounds Read6.5 MediumN/A0%Dec 2, 2025
CVE-2025-13877: Use of Hard-coded Cryptographic Key5.6 Medium2.9 Low0%Dec 2, 2025
CVE-2025-13372: Improper Neutralization of Special Elements used in an SQL Command4.3 MediumN/A0%Dec 2, 2025
CVE-2025-12630: Undefined Security Weakness4.9 MediumN/A0%Dec 2, 2025
CVE-2025-59705: Improper Privilege Management6.8 MediumN/A0%Dec 2, 2025
CVE-2025-59702: Observable Discrepancy7.2 HighN/A0%Dec 2, 2025
CVE-2025-59701: Cleartext Storage of Sensitive Information4.1 MediumN/A0%Dec 2, 2025
CVE-2025-59700: Insufficient Verification of Data Authenticity3.9 LowN/A0%Dec 2, 2025
81351-81375 of 400424