Metasploit
1,875 exploits
Active since Aug 1990
v0pCr3w (Web Shell) - Remote Code Execution (Metasploit)
Total.js CMS 12.0.0 - Authenticated RCE
CVSS 9.9
tinc < 1.0.21 and 1.1 < 1.1pre7 - Authenticated Stack-Based Buffer Overflow via Large TCP Packet
TeamCity Agent - XML-RPC Command Execution (Metasploit)
TeamCity Agent - XML-RPC Command Execution (Metasploit)
Symantec Workspace Streaming <7.5.0.749 - SSRF
Oracle Java SE/Jav for Bus <6 Update 21 - Info Disclosure
Sun Java System Web Server 7.0 Update 7 - Stack-Based Buffer Overflow via WebDAV OPTIONS Request
Sun Java JRE getSoundbank file:// URI Buffer Overflow
Oracle Java SE/Jav for Bus <6 - Info Disclosure
Sun Java JRE AWT setDiffICM Buffer Overflow
Sun Java Calendar Deserialization Privilege Escalation
HP-UX - Unauthenticated Remote Login via Default Null Password
Squiggle 1.7 - SVG Browser Java Code Execution (Metasploit)
Square Squash - Remote Code Execution via YAML in Namespace or Sourcemap Parameter
Splunk 5.0 - Custom App Remote Code Execution (Metasploit)
DELL SonicWALL Analyzer 7.0, GMS 4.1-7.0, UMA 5.1-7.0, ViewPoint 4.1-6.0 - Authentication Bypass
CVSS 9.8
Solaris - Unauthenticated Remote Privilege Escalation via sadmind AUTH_SYS Spoofing
Snort < 2.6.1.3 and 2.7 < beta 2 - Remote Code Execution via DCE/RPC Preprocessor
Sun Java Calendar Deserialization Privilege Escalation
SAP SOAP RFC - SXPG_COMMAND_EXECUTE Remote Command Execution (Metasploit)
SAP SOAP RFC - SXPG_CALL_SYSTEM Remote Command Execution (Metasploit)
rubyonrails/web_console < 2.1.2 and rubygems/web-console < 2.1.3 - Improper Access Control via X-Forwarded-For Header
Ruby on Rails JSON Processor YAML Deserialization Code Execution
Ruby on Rails JSON Processor YAML Deserialization Code Execution