Metasploit
1,875 exploits
Active since Aug 1990
Ruby on Rails 2.3.x-2.3.15 and 3.0.x-3.0.19 - Remote Code Execution via YAML Deserialization
Ruby on Rails Dynamic Render File Upload Remote Code Execution
CVSS 7.5
Rocket ServerGraph 1.2 - Path Traversal
RealNetworks Helix Universal Server 9.0.2.768 - Remote Code Execution via RTSP/HTTP Request Buffer Overflow
Railo < 4.2.1.000 - Remote File Inclusion via Thumbnail CFM Request
CVSS 8.8
PostgreSQL 9.3-11.2 - Authenticated OS Command Injection via COPY TO/FROM PROGRAM
CVSS 7.2
PHP < 4.4.4 - Remote Code Execution via Long String to unserialize Function
OrientDB 2.2.2 < 2.2.22 - Remote Code Execution (Metasploit)
Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, 12.2.1.0 - Remote Code Execution via T3 Protocol Deserialization
CVSS 9.8
Oracle WebLogic Server 10.3.6.0.0 and 12.1.3.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
Oracle WebLogic wls-wsat Component Deserialization RCE
CVSS 7.5
Opera - Stored Cross-Site Scripting via History Search Database
Opera 9 - Configuration Overwrite (Metasploit)
Novell ZENworks Configuration Management (ZCM) <10.3 - Path Traversal
Novell ZENworks Configuration Management < 11.2.4 - Directory Traversal & Arbitrary File Upload
Micro Focus Novell Service Desk <7.2 - Path Traversal
CVSS 7.2
NetIQ eDirectory <8.8.7.2 - Buffer Overflow
nostromo_nhttpd <= 1.9.6 - Remote Code Execution via Directory Traversal in http_verify
CVSS 9.8
NodeJS Debugger - Command Injection (Metasploit)
Nanopool Claymore Dual Miner <7.3 - RCE
CVSS 7.5
Mozilla Firefox <1.5.0.5 & SeaMonkey <1.0.3 - RCE
Firefox 3.5 - Remote Code Execution via TraceMonkey JIT Escape Function
Mozilla Firefox < 28.0 - Popup Blocker Bypass
CVSS 9.8
Firefox < 21.0 and Firefox ESR < 17.0.6 - Cross-Site Scripting via Chrome Object Wrapper
Firefox < 34.0.5 and SeaMonkey < 2.31 - Remote Code Execution via XrayWrapper DOM Interaction