A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. These vulnerabilities are utilized by our vulnerability management tool InsightVM. The exploits are all included in the Metasploit framework and utilized by our penetration testing tool, Metasploit Pro. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 861 - 880 of 5,754 in total
PlaySMS sendfromfile.php Authenticated "Filename" Field Code Execution
Disclosed: May 21, 2017
module
Explore
PlaySMS import.php Authenticated CSV File Upload Code Execution
Disclosed: May 21, 2017
module
Explore
Joomla Component Fields SQLi Remote Code Execution
Disclosed: May 17, 2017
module
Explore
Octopus Deploy Authenticated Code Execution
Disclosed: May 15, 2017
module
Explore
LabF nfsAxe 3.7 FTP Client Stack Buffer Overflow
Disclosed: May 15, 2017
module
Explore
HPE iMC dbman RestoreDBase Unauthenticated RCE
Disclosed: May 15, 2017
module
Explore
HPE iMC dbman RestartDB Unauthenticated RCE
Disclosed: May 15, 2017
module
Explore
Windows UAC Protection Bypass (Via FodHelper Registry Key)
Disclosed: May 12, 2017
module
Explore
Veritas/Symantec Backup Exec SSL NDMP Connection Use-After-Free
Disclosed: May 10, 2017
module
Explore
DnsAdmin ServerLevelPluginDll Feature Abuse Privilege Escalation
Disclosed: May 08, 2017
module
Explore
Intel AMT Digest Authentication Bypass Scanner
Disclosed: May 05, 2017
module
Explore
Serviio Media Server checkStreamUrl Command Execution
Disclosed: May 03, 2017
module
Explore
Crypttech CryptoLog Remote Code Execution
Disclosed: May 03, 2017
module
Explore
WordPress PHPMailer Host Header Command Injection
Disclosed: May 03, 2017
module
Explore
Ghostscript Type Confusion Arbitrary Command Execution
Disclosed: April 27, 2017
module
Explore
Jenkins CLI Deserialization
Disclosed: April 26, 2017
module
Explore
Symantec Messaging Gateway Remote Code Execution
Disclosed: April 26, 2017
module
Explore
October CMS Upload Protection Bypass Code Execution
Disclosed: April 25, 2017
module
Explore
Solaris 'EXTREMEPARR' dtappgather Privilege Escalation
Disclosed: April 24, 2017
module
Explore
WePresent WiPG-1000 Command Injection
Disclosed: April 20, 2017
module
Explore