Metasploit
1,875 exploits
Active since Aug 1990
Elasticsearch < 1.2 - Remote Code Execution via Dynamic Scripting
CVSS 8.1
Elasticsearch <1.3.8, <1.4.3 - Command Injection
CVSS 9.8
DCNM-SAN Server <6.2(1) - Path Traversal
Cisco Data Center Network Manager Unauthenticated Remote Code Execution
CVSS 5.3
Atlassian Jira - (Authenticated) Upload Code Execution (Metasploit)
Atlassian Jira - (Authenticated) Upload Code Execution (Metasploit)
Apache Struts 2.0.0-2.3.16 - Remote Code Execution via DebuggingInterceptor
Apache Spark - (Unauthenticated) Command Execution (Metasploit)
Apache Spark - (Unauthenticated) Command Execution (Metasploit)
Apache Roller < 5.0.2 - Remote Code Execution via OGNL Injection in getText Methods
Apache Jetspeed Arbitrary File Upload
CVSS 8.8
ActiveMQ web shell upload
CVSS 9.8
iPhone OS < 9.3.5 - Remote Code Execution via WebKit Memory Corruption
CVSS 8.8
Adobe Acrobat and Reader 8.x < 8.2.1 and 9.x < 9.3.1 - Remote Code Execution
CVSS 7.8
Adobe Acrobat and Reader 8.x < 8.2.1 and 9.x < 9.3.1 - Remote Code Execution
CVSS 7.8
HP-UX 10.20-11.11 - Buffer Overflow in lp Subsystem
Google Mini Search Appliance - Remote Code Execution via XSLT Style Sheet Select Attribute
D-Link DCS-931L Firmware < 1.04 - Authenticated Remote Code Execution via File Upload
Xerox Multifunction Printers (MFP) - 'Patch' DLM (Metasploit)
QNAP Transcode Server - Command Execution (Metasploit)
Cisco RVS4000, WRVS4400N, and WAP4410N Firmware - Remote Code Execution via Test Interface
Supermicro Onboard IPMI CGI Vulnerability Scanner
Synology DiskStation Manager < 5.2-5967-5 - Authenticated Command Injection via smart.cgi Disk Field
CVSS 8.8
Linksys WVBR0 < 1.0.41 - Unauthenticated Remote Code Execution via Web Management Portal
CVSS 9.8
HP SAN/iQ < 9.5 - Unauthenticated Remote Access via Hardcoded Password