Vulnerability & Exploit Database

Try Surface Command Get a continuous 360° view of your attack surface

A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. The exploits are all included in the Metasploit framework. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 61 - 80 of 6,012 in total
Apache OFBiz forgotPassword/ProgramExport RCE
Disclosed: May 30, 2024
module
Explore
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
Disclosed: May 25, 2024
module
Explore
Ivanti EPM RecordGoodApp SQLi RCE
Disclosed: May 24, 2024
module
Explore
WordPress Hash Form Plugin RCE
Disclosed: May 23, 2024
module
Explore
Atlassian Confluence Administrator Code Macro Remote Code Execution
Disclosed: May 21, 2024
module
Explore
Cacti Import Packages RCE
Disclosed: May 12, 2024
module
Explore
DIAEnergie SQL Injection (CVE-2024-4548)
Disclosed: May 06, 2024
module
Explore
Flowmon Unauthenticated Command Injection
Disclosed: April 23, 2024
module
Explore
Apache HugeGraph Gremlin RCE
Disclosed: April 22, 2024
module
Explore
FortiNet FortiClient Endpoint Management Server FCTID SQLi to RCE
Disclosed: April 21, 2024
module
Explore
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
Disclosed: April 12, 2024
module
Explore
Chaos RAT XSS to RCE
Disclosed: April 10, 2024
module
Explore
AVideo WWBNIndex Plugin Unauthenticated RCE
Disclosed: April 09, 2024
module
Explore
pgAdmin Binary Path API RCE
Disclosed: March 28, 2024
module
Explore
Code Reviewer
Disclosed: March 22, 2024
module
Explore
Progress Flowmon Local sudo privilege escalation
Disclosed: March 19, 2024
module
Explore
Kemp LoadMaster Local sudo privilege escalation
Disclosed: March 19, 2024
module
Explore
Kemp LoadMaster Unauthenticated Command Injection
Disclosed: March 19, 2024
module
Explore
Gibbon School Platform Authenticated PHP Deserialization Vulnerability
Disclosed: March 18, 2024
module
Explore
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
Disclosed: March 16, 2024
module
Explore