Metasploit
1,875 exploits
Active since Aug 1990
AWStats Totals 1.0-1.14 - Remote Code Execution via Sort Parameter
Basic Analysis and Security Engine <= 1.2.4 - Remote Code Execution via BASE_path Parameter
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
CVSS 8.8
PHPStudy - Backdoor Remote Code execution (Metasploit)
phpMyAdmin 4.8.x <4.8.2 - Code Injection
CVSS 8.8
phpMyAdmin <3.5.8 and <4.0.0-rc3 - Authenticated RCE
phpFileManager 0.9.8 - Remote Code Execution (Metasploit)
PhpCollab < 2.5.1 - Authenticated Arbitrary File Upload via Client Logo Upload
CVSS 8.8
PHP 7.1.x < 7.1.33, 7.2.x < 7.2.24, 7.3.x < 7.3.11 - Remote Code Execution via FPM Buffer Overflow
CVSS 8.7
PHP Utility Belt - Remote Code Execution (Metasploit)
PHP IRC Bot pbot - 'eval()' Remote Code Execution (Metasploit)
PHP < 5.3.13 and 5.4.x < 5.4.3 - Denial of Service via Malformed CGI Query String
Phoenix Exploit Kit - Remote Code Execution (Metasploit)
Phoenix Exploit Kit - Remote Code Execution (Metasploit)
pfSense 2.4.1 - Cross-Site Request Forgery Error Page Clickjacking (Metasploit)
Pandora FMS < 3.1 - Unauthenticated Authentication Bypass via Empty loginhash_pwd
OpenX Ad Server 2.8.10 - Remote Code Execution via Backdoor in flowplayer-3.1.1.min.js
CVSS 9.8
OpenX < 2.8.1 - Authenticated Arbitrary File Upload and Remote Code Execution via Banner Edit
iTop 1.1.181 and 1.2.0-RC-282 - Cross-Site Scripting via Multiple Input Vectors
iTop 1.1.181 and 1.2.0-RC-282 - Cross-Site Scripting via Multiple Input Vectors
October CMS <build 412 - Code Injection
CVSS 7.2
NUUO NVRmini Firmware - Remote Command Execution via uploaddir Parameter
CVSS 9.8
Nibbleblog < 4.0.4 - Remote Code Execution via My Image Plugin File Upload
Network Shutdown Module 3.21 - 'sort_values' Remote PHP Code Injection (Metasploit)
Navigate CMS 2.8 - Authenticated Remote Code Execution via Directory Traversal in navigate_upload.php
CVSS 8.8