Metasploit
1,875 exploits
Active since Aug 1990
W3 Total Cache < 0.9.2.8 - Remote PHP Code Execution
CVSS 9.8
ThemePunch Slider Revolution <3.0.96 & Showbiz Pro <1.7.1 - RCE
WordPress Plugin Responsive Thumbnail Slider - Arbitrary File Upload (Metasploit)
reflex_gallery < 3.1.3 - Unauthenticated Arbitrary PHP File Upload via FileUploader
PHPMailer Sendmail Argument Injection
CVSS 9.8
WordPress Plugin N-Media Website Contact Form - Arbitrary File Upload (Metasploit)
MailPoet Newsletters <2.6.7 - Auth Bypass
Infusionsoft Gravity Forms 1.5.3-1.5.10 - Unauthenticated Arbitrary File Upload and Remote Code Execution
WordPress Plugin Database Backup < 5.2 - Remote Code Execution (Metasploit)
Creative Contact Form < 1.0.0 - Unauthenticated Arbitrary File Upload via jQuery File Upload Plugin
CVSS 9.8
WordPress Plugin Ajax Load More 2.8.1.1 - PHP Upload (Metasploit)
WordPress <= 5.0.3 - Authenticated Path Traversal via Image Crop Filename
CVSS 6.5
Western Digital MyCloud PR4100 2.30.172 - Unauthenticated Arbitrary File Write and RCE via Multi Uploadify
CVSS 9.8
vtiger CRM < 5.4.0 - PHP Code Injection via vtigerolservice.php
CVSS 9.8
vtiger CRM 5.3 and 5.4 - Unrestricted Upload of File with Dangerous Type
CVSS 8.8
vtiger CRM < Security Patch 2 - Unauthenticated Remote Code Execution via Install Module Re-Installation
vBulletin 5.0.0 Beta 11 and earlier - Authenticated SQL Injection via nodeid Parameter
AutoSec Tools V-CMS 1.0 - Remote Code Execution via Unrestricted File Upload in Inline Image Upload
TWiki Debugenableplugins Remote Code Execution
CVSS 9.1
Tuleap < 9.6 - Remote Code Execution via User::getRecentElements() Unserialize
CVSS 8.8
Tuleap < 7.7 - Authenticated PHP Object Injection via Project Registration Data Parameter
Th3 MMA - 'mma.php' Backdoor Arbitrary File Upload (Metasploit)
TestLink 1.9.3 - Arbitrary File Upload (Metasploit)
STUNSHELL (Web Shell) - Remote Code Execution (Metasploit)
STUNSHELL (Web Shell) - Remote Code Execution (Metasploit)