Metasploit Exploits

3,189 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-21554 METASPLOIT CRITICAL ruby
CVE-2023-21554 - QueueJumper - MSMQ RCE Check
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
by Wayne Low, Haifei Li, Bastian Kanbach <[email protected]>
CVSS 9.8
CVE-1999-0531 METASPLOIT ruby
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO.
CVE-1999-0502 METASPLOIT ruby
Unix - Info Disclosure
A Unix account has a default, null, blank, or missing password.
by todb
CVE-1999-0502 METASPLOIT ruby
Unix - Info Disclosure
A Unix account has a default, null, blank, or missing password.
by theLightCosine
CVE-2017-12635 METASPLOIT CRITICAL ruby
Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. The JSON parser differences result in behaviour that if two 'roles' keys are available in the JSON, the second one will be used for authorising the document write, but the first 'roles' key is used for subsequent authorization for the newly created user. By design, users can not assign themselves roles. The vulnerability allows non-admin users to give themselves admin privileges.
by Max Justicz
CVSS 9.8
CVE-2007-0977 METASPLOIT ruby
IBM Lotus Domino R5-R6 WebMail - Info Disclosure
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.
CVE-2014-7992 METASPLOIT ruby
Cisco DLSw Information Disclosure Scanner
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.
by Tate Hansen, John McLeod, Kyle Rainey
CVE-2025-14847 METASPLOIT HIGH ruby
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
by Alexander Hagenah, Diego Ledda, Joe Desimone
CVSS 7.5
CVE-1999-0502 METASPLOIT ruby
Unix - Info Disclosure
A Unix account has a default, null, blank, or missing password.
by todb
CVE-2013-1899 METASPLOIT ruby
PostgreSQL Database Name Command Line Flag Injection
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary code, via a connection request using a database name that begins with a "-" (hyphen).
by hdm
CVE-2017-7922 METASPLOIT HIGH ruby
Cambium Networks Epmp 1000 Firmware - Improper Privilege Management
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes.
by Karn Ganeshen
CVSS 7.6
CVE-2017-5262 METASPLOIT HIGH ruby
Cambium Networks cnPilot <4.3.2-R4 - Info Disclosure
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.
by Karn Ganeshen
CVSS 8.0
CVE-1999-0508 METASPLOIT ruby
Router/FW - Info Disclosure
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
CVE-1999-0508 METASPLOIT ruby
Router/FW - Info Disclosure
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
CVE-2014-4863 METASPLOIT ruby
Arris Touchstone DG950A <7.10.131 - Info Disclosure
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
by Deral, Heiland
CVE-2018-10933 METASPLOIT CRITICAL ruby
libssh Authentication Bypass Scanner
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
by Peter Winter-Smith, wvu
CVSS 9.1
CVE-1999-0502 METASPLOIT ruby
Unix - Info Disclosure
A Unix account has a default, null, blank, or missing password.
by todb, RageLtMan
CVE-2015-7755 METASPLOIT CRITICAL ruby
Juniper ScreenOS <6.3.0r21 - RCE
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
by hdm
CVSS 9.8
CVE-2008-5161 METASPLOIT ruby
SSH Version Scanner
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.
CVE-2018-16158 METASPLOIT CRITICAL ruby
Eaton Power Xpert Meter 4000 Firmware - Hard-coded Credentials
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.
by BrianWGray
CVSS 9.8
CVE-2016-1909 METASPLOIT CRITICAL ruby
Fortinet <5.0.12 - Hardcoded Passphrase
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.
CVSS 9.8
CVE-2018-15473 METASPLOIT MEDIUM ruby
Openbsd Openssh < 7.7 - Race Condition
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
by kenkeiras, Dariusz Tytko, Michal Sajdak, Qualys, wvu
CVSS 5.3
CVE-1999-0502 METASPLOIT ruby
Unix - Info Disclosure
A Unix account has a default, null, blank, or missing password.
CVE-2012-4356 METASPLOIT ruby
Sielcosistemi Winlog Pro < 2.07.16 - Path Traversal
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read operation with opcode (1) 0x96, (2) 0x97, or (3) 0x98.
by Luigi Auriemma, juan vazquez
CVE-2011-1900 METASPLOIT ruby
InduSoft Web Studio <7.0+Patch 1 - Path Traversal
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.
by Unknown, juan vazquez