Metasploit
1,875 exploits
Active since Aug 1990
Sophos Web Appliance Firmware < 3.8.2 - Authenticated Admin Password Change
Simple E-Document 3.0-3.1 - File Upload
Pandora FMS <= 5.0RC1 - Unauthenticated Remote Command Execution via Anyterm p Parameter
Kloxo < 6.1.12 - Unauthenticated SQL Injection via Login-Name Parameter
Array Networks vAPV/vxAG <8.3.2.17-9.2.0.34 - Privilege Escalation
eScan Web Management Console <5.5-2 - Command Injection
D-Link DSP-W215 1.02 - Unauthenticated Stack-based Buffer Overflow via /common/info.cgi HTTP POST Request
CVSS 9.8
HybridAuth 2.0.9-2.2.2 - Unauthenticated Remote Code Execution via install.php Config Injection
Pandora FMS <5.0 SP2 - SQL Injection
i-Ftp 2.20 - Stack-based Buffer Overflow via Schedule.xml Time Attribute
Dell KACE K1000 <5.4.76849-5.5.90547 - File Upload
VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Command Injection
VICIDIAL < 2.7 - SQL Injection via Campaign Variable in SCRIPT_multirecording_AJAX.php
DataLife Engine 9.7 - Remote Code Execution via catlist[] Parameter
HP SAN/iQ < 9.5 - Authenticated OS Command Injection via Ping Parameter
XAMPP < 1.7.3 - Authenticated Remote Code Execution via WebDAV PHP Upload
Sysax Multi Server <5.55 - Buffer Overflow
CVSS 9.8
Dolibarr ERP/CRM <= 3.1.1-3.2.0 - Command Injection
RabidHamster R4 v1.25 - Buffer Overflow
Lattice Semiconductor ispVM System v18.0.2 - Buffer Overflow
PHP Volunteer Management System v1.0.2 - Code Injection
DC/OS Marathon < 1.9.0 - Docker Root Mount Code Execution
Oracle Application Testing Suite - Unspecified Vuln
Watchguard XCS <10.0 - SQL Injection
Adobe Flash Player <14.x - Memory Corruption
CVSS 9.8