Metasploit
1,875 exploits
Active since Aug 1990
STUNSHELL (Web Shell) - PHP Remote Code Execution (Metasploit)
STUNSHELL (Web Shell) - PHP Remote Code Execution (Metasploit)
SPIP - 'connect' PHP Injection (Metasploit)
Shopware < 5.3.4 - PHP Object Instantiation and XXE via ProductStream Controller
CVSS 6.5
Sflog! CMS 1.0 - Arbitrary File Upload (Metasploit)
SePortal 2.4 - SQL Injection via poll_id or sp_id Parameter
CodeIgniter <2.2.0 - Info Disclosure
CVSS 9.8
ProjectSend r100-r561 - Unauthenticated Arbitrary File Upload and Remote Code Execution via process-upload.php
PolarBear CMS 2.5 - Unauthenticated Arbitrary File Upload via upload.php
CVSS 9.8
PlaySMS 1.4 - Remote Code Execution
CVSS 8.8
playsms < 1.4.3 - Unauthenticated Remote Code Execution via Template Injection
CVSS 9.8
PlaySMS 1.4 - Remote Code Execution
CVSS 9.8
Piwik 2.14.0/2.16.0/2.17.1/3.0.1 - Superuser Plugin Upload (Metasploit)
PineApp Mail-SeCure - 'test_li_connection.php' Arbitrary Command Execution (Metasploit)
PineApp Mail-SeCure - 'ldapsyncnow.php' Arbitrary Command Execution (Metasploit)
pimcore < 5.7.1 - Authenticated Remote Code Execution via Unserialize in Bulk-Commit Endpoint
CVSS 8.8
activeCollab Chat Module < 1.5.2 - Authenticated Remote Code Execution via Message Text Parameter
Samba < 2.2.8a and 2.0.10 - Remote Code Execution via call_trans2open Buffer Overflow
4D WebSTAR <5.3.2 - Buffer Overflow
EvoLogical EvoCam 3.6.6-3.6.7 - Remote Code Execution via Long GET Request
Samba 3.0.0-3.0.25rc3 - Buffer Overflow
Mozilla Firefox <3.5.19 & SeaMonkey <2.0.14 - Use After Free
mDNSResponder 10.4.0/10.4.8 (OSX) - UPnP Location Overflow (Metasploit)
Knox Arkeia Server Backup 5.3.x - Remote Code Execution via Type 77 Request
AppleFileServer <10.3.3 - Buffer Overflow