Metasploit
1,875 exploits
Active since Aug 1990
NAS4Free <= 9.1.0.1.804 - Authenticated Remote Code Execution via Advanced Execute Command Feature
MantisBT - Remote Code Execution via XmlImportExport Plugin Preg Replace
Mantis < 1.1.4 - Authenticated Remote Code Execution via Sort Parameter
LotusCMS 3.0 - 'eval()' Remote Command Execution (Metasploit)
Kaltura Server < mercury-13.1.0 - Remote Code Execution via Hardcoded Cookie Secret
CVSS 9.8
Joomla! <2.5.14, <3.1.5 - Auth Bypass
Akeeba Restore <3.3.4 - Info Disclosure
Joomla! 3.2-3.4.3 - SQL Injection
ISPConfig 3.0.5.2 - Arbitrary PHP Code Execution
CVSS 8.8
Invision Power Board 3.1.x-3.3.x core.php - Impact Unknown
Idera Up.Time Monitoring Station 7.4 - 'post2file.php' Arbitrary File Upload (Metasploit)
IBM Informix Open Admin Tool <12.1 - RCE
CVSS 9.8
Horde Application Framework < 5.1.1 - Remote Code Execution via Serialized Object in _formvars
GLPI < 0.84.2 - Cross-Site Request Forgery and SQL Injection via Install Script
GitList 0.6.0 - Argument Injection (Metasploit)
GitList 0.6.0 - Argument Injection (Metasploit)
GetSimple CMS < 3.3.15 - Remote Code Execution via Theme Edit File Upload
CVSS 9.8
eXtplorer 2.1 - Arbitrary File Upload (Metasploit)
elFinder < 2.1.48 - OS Command Injection in PHP Connector
CVSS 9.8
Drupal 7.0.0-7.61.0 8.5.0-8.5.10 8.6.0-8.6.9 - Remote Code Execution via Unsanitized Field Data
CVSS 8.1
Dexter (CasinoLoader) - SQL Injection (Metasploit)
ZPanel through 10.1.0 - Remote Code Execution
CVSS 7.8
X7 Chat <2.0.5.1 - Authenticated RCE
WP Symposium 14.11 - Unauthenticated Arbitrary File Upload via UploadHandler.php
WordPress Plugin Work The Flow - Arbitrary File Upload (Metasploit)