Metasploit
1,875 exploits
Active since Aug 1990
Apache Tomcat 5.5.0-5.5.28 and 6.0.0-6.0.20 - Unauthenticated Privilege Escalation via Default Blank Admin Password
IBM Rational Quality Manager and Rational Test Lab Manager - Remote Code Execution via Default Tomcat ADMIN Password
Apache Struts 2.0.0-2.1.8.1 - Remote Code Execution via OGNL Context Variable Manipulation
Apache Commons BeanUtils <1.9.2 - RCE
Apache Struts 2.3.x < 2.3.32 and 2.5.x < 2.5.10.1 - Remote Code Execution via Jakarta Multipart Parser
CVSS 9.8
Apache Struts < 2.2.3.1 - Remote Code Execution via ExceptionDelegator OGNL Expression Injection
CVSS 9.8
Apache Struts 2.1.x and 2.3.x - Remote Code Execution via ActionMessage Field Value
CVSS 9.8
Apache Struts 2 Namespace Redirect OGNL Injection
CVSS 8.1
Apache Archiva 1.3-1.3.8 - Remote Code Execution via OGNL Expression Injection
CVSS 9.8
Apache Struts 2.3.19-2.3.20.2, 2.3.21-2.3.24.1, 2.3.25-2.3.28 - Remote Code Execution
CVSS 9.8
Apache Struts 2.0.0-2.3.14.1 - Remote Code Execution via OGNL Injection in URL/A Tag
CVSS 8.1
Apache Struts 2.0.0-2.3.16.1 and struts2-core < 2.3.20 - Remote Code Execution via CookieInterceptor
Apache Struts <2.3.1.2 - Command Injection
CVSS 9.8
Redmine SCM Repository 0.9.x/1.0.x - Arbitrary Command Execution (Metasploit)
Apple <macOS High Sierra - Privilege Escalation
CVSS 8.1
Mac OS X Feedback Assistant Race Condition
CVSS 7.0
Rancher Server - Docker Daemon Code Execution (Metasploit)
Unitrends UEB http api remote code execution
CVSS 9.8
Unitrends UEB bpserverd authentication bypass RCE
CVSS 9.8
Samba 3.0.0-3.3.12 - Remote Code Execution via SMB1 Packet Chaining
Samba < 2.2.8a and 2.0.10 - Remote Code Execution via call_trans2open Buffer Overflow
Linux Kernel 4.6.3 Netfilter Privilege Escalation
CVSS 7.8
TP-Link Archer A7 Firmware <190726 - RCE
CVSS 8.8
D-Link DIR-850L - OS Command Execution (Metasploit)
D-Link DIR-859 1.05 and 1.06B01 - Unauthenticated OS Command Injection via M-SEARCH Method
CVSS 9.8