Metasploit
1,875 exploits
Active since Aug 1990
Zimbra 7.2.2-8.0.2 - Path Traversal
Holding Pattern < 0.6 - Unauthenticated Arbitrary File Upload via admin/upload-file.php
WebCalendar < 1.2.5 - Remote Code Execution via form_single_user_login Parameter
CVSS 9.8
Movable Type <5.2.12 & <6.0.7 - Code Injection
Safari Proxy Object Type Confusion
CVSS 8.8
VMware Fusion <11.5.2 - Privilege Escalation
CVSS 7.8
Mac OS X TimeMachine (tmdiagnose) Command Injection Privilege Escalation
CVSS 7.8
Mac OS X libxpc MITM Privilege Escalation
CVSS 7.8
SpamAssassin - Remote Code Execution via Crafted Message with Virtual Pop Username
Redhat Openstack < 1.2.0 - Access Control
D-Link Routers - Remote Code Execution via ping.ccp
CVSS 9.8
Centreon 2.5.1 and Centreon Enterprise Server 2.2 - Remote Code Execution via session_id or template_id Parameter
ZPanel 10.0.0.2 htpasswd Module - 'Username' Command Execution (Metasploit)
Synacor Zimbra Collaboration Suite <8.7.11p10 - XXE
CVSS 9.8
Zabbix Server <1.8 - Command Injection
Zabbix 2.0.9 - Remote Command Execution
CVSS 8.8
HP-UX - Remote Code Execution via wu-ftpd SITE EXEC Format String
Wireshark 0.9.15-1.0.10 and 1.2.0-1.2.5 - Denial of Service via Malformed LWRES Packet
VMTurbo Operations Manager <4.6 - Command Injection
VICIDIAL dialer <2.8-403a, 2.7, 2.7RC1 - Info Disclosure
University of Washington imapd 4.7 - Authenticated Buffer Overflow via LIST Command
UnrealIRCd 3.2.8.1 - Remote Code Execution via Trojaned DEBUG3_DOLOG_SYSTEM Macro
Unreal Engine - RCE
unraid 6.8.0 - Authentication Bypass
CVSS 7.5
Kaseya Unitrends Backup < 10.1 - Unauthenticated Command Injection via /api/hosts Parameter
CVSS 9.8