Metasploit
1,875 exploits
Active since Aug 1990
rconfig 3.9.2 - OS Command Injection via ajaxServerSettingsChk.php rootUname Parameter
CVSS 9.8
Quest Privilege Manager for Unix < 6.0.0-50 - Buffer Overflow via ACT_ALERT_EVENT Request
CVSS 9.8
QNAP Q'center < 1.7.1063 - Authenticated OS Command Injection via Change Password
CVSS 7.2
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8
Google Chrome < 39.0.2171.65 - Denial of Service or Other Impact
ProFTPD 1.3.5 - Unauthenticated Arbitrary File Read and Write via mod_copy Site Commands
ProFTPD - Stack-Based Buffer Overflow via TELNET IAC Escape Character
ProFTPD - Stack-Based Buffer Overflow via TELNET IAC Escape Character
ProFTPD < 1.3.0 - Stack-based Buffer Overflow in sreplace Function
PoPToP PPTP Server - Denial of Service via Invalid Control Packet Length
Laravel Framework < 5.5.40 and 5.6.x < 5.6.30 - Remote Code Execution via Unserialize of X-XSRF-TOKEN
CVSS 8.1
University of Washington IMAP Toolkit 2007f - Command Injection
CVSS 7.5
PeerCast < 0.1217 - Remote Code Execution via Long HTTP GET Parameter
Oracle VM Server Virtual Server Agent Command Injection
OpenSMTPD 6.6 - Remote Code Execution via MAIL FROM Field
CVSS 9.8
openSIS 4.5-5.2 - Remote Code Execution via ajax.php modname Parameter
OpenNMS - Java Object Unserialization Remote Code Execution (Metasploit)
OpenMRS Java Deserialization RCE
CVSS 9.8
openmediavault - Authenticated Remote Code Execution via Cron Service Username Parameter
CVSS 8.8
op5 7.1.9 - Configuration Command Execution (Metasploit)
ntpd < 4.0.99k - Buffer Overflow via Long readvar Argument
nginx 1.3.9-1.4.0 - Remote Code Execution via Chunked Transfer-Encoding
Nexus Repository Manager Java EL Injection RCE
CVSS 8.8
NetSupport Manager Agent <=11.00 Remote Code Execution via Long Control Hostname
Nagios Core < 3.4.4 / Icinga 1.6.x < 1.6.2, 1.7.x < 1.7.4, 1.8.x < 1.8.4 - Stack-Based Buffer Overflow