Metasploit
1,875 exploits
Active since Aug 1990
PhpTax 0.8 - Unauthenticated Remote Code Execution via drawimage.php pfilez Parameter
Project Pier <0.8.8 - Unauthenticated RCE
Turbo FTP Server <1.30.823-1.30.826 - Buffer Overflow
Narcissus backend.php - release Parameter Command Injection
Maxthon3 < 3.2.2 build 1000 - Cross-Context Scripting via about:history Page
BlazeVideo HDTV Player Pro v6.6.0.3 - Buffer Overflow
FreeFloat FTP Server - Unauthenticated RCE
CVSS 9.8
Nagios XI Network Monitor <1.3 - Command Injection
Netwin SurgeFTP <23c8 - Command Injection
WP-Property < 1.35.0 - Unauthenticated Arbitrary File Upload via uploadify.php
WordPress Plugin Asset-Manager < 2.0 - Unauthenticated Arbitrary File Upload via upload.php
WordPress Advanced Custom Fields <= 3.5.1 - Remote File Inclusion Code Execution
ComSndFTP FTP Server <1.3.7 Beta - Code Injection
Umbraco CMS < 4.7.1 - Unauthenticated Remote Code Execution via codeEditorSave.asmx SaveDLRScript Path Traversal
CVSS 9.8
Simple Web Server 2.2 rc2 - Buffer Overflow
EGallery 1.2 - Unauthenticated Arbitrary File Upload via uploadify.php
Photodex ProShow Producer <5.0.3256 - Buffer Overflow
CuteFlow < 2.11.2 - Unauthenticated Arbitrary File Upload via restart_circulation_values_write.php
Measuresoft ScadaPro <4.0.0 - Buffer Overflow
Novell ZENworks Configuration Management 11.1 and 11.1a - Remote Code Execution via Preboot Service Opcode 0x6c
Sunway ForceControl <6.1 SP3 - Buffer Overflow
Foxit PDF Reader < 4.3.1.0218 - Code Injection
RealArcade 2.6.0.445 ActiveX - Exec Method Command Execution
AOL Desktop < 9.6 - Stack-based Buffer Overflow via RTX Hyperlink Tag
Spreecommerce < 0.50.x - Unauthenticated Remote Code Execution via API Search Parameter
CVSS 9.8