Metasploit
1,875 exploits
Active since Aug 1990
Unitrends UEB http api remote code execution
CVSS 9.8
Linux Kernel <4.11.5 - Memory Corruption
CVSS 7.4
IBM QRadar 7.2-7.3 - Improper Access Control
CVSS 4.2
D-Link DSL-2750B <1.05 - Command Injection
CVSS 9.8
MVPower TV-7104HE and TV7108HE Firmware - Unauthenticated Remote Code Execution via Web Shell
CVSS 9.8
Joomla! 3.2-3.4.4 - SQL Injection via list[select] Parameter
Joomla! 3.2-3.4.3 - SQL Injection
GoAutoDial GoAdmin CE - SQL Injection via User Credentials or PATH_INFO
Xdebug < 2.5.5 - Unauthenticated OS Command Injection via Remote Debugger Interface
ManageEngine Desktop Central < 9.0 - Remote Code Execution via File Upload Path Traversal
D-Link DIR-300, DIR-600 < 2.17b01, DIR-645 < 1.04b11, DIR-845 < 1.02b03, DIR-865 - OS Command Injection
CVSS 9.8
Symantec Endpoint Protection Manager 11.0-11.0.7405.1424 and 12.1-12.1.4023.4080 - Authenticated SQL Injection
MiniWeb HTTP Server <= Build 300 - File Upload
Corel PDF Fusion 1.11 - Buffer Overflow
SolarWinds Backup Profiler < 5.1.2 - SQL Injection via LoginServlet loginName Parameter
CVSS 9.8
WebPageTest < 2.6 - Remote Code Execution via Unrestricted File Upload in resultimage.php
Zenoss Core 3.x - Command Injection
Cyclope Employee Surveillance Solution 6.x - SQL Injection
E-Mail Security Virtual Appliance ESVA_2057 - Unauthenticated OS Command Injection via learn-msg.cgi id Parameter
XODA 0.4.5 - Unauthenticated Arbitrary PHP File Upload via Multipart Form Data
MobileCartly 1.0 - Unauthenticated Arbitrary File Creation via savepage.php
WAN Emulator 2.3 - Unauthenticated OS Command Injection via result.php pc Parameter
Openfiler 2.x - Authenticated OS Command Injection via system.html Device Parameter
ZEN Load Balancer <3.0-rc1 - Command Injection
Auxilium RateMyPet - Unauthenticated Arbitrary File Upload via Banner Upload Feature