Vulnerability & Exploit Database

A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. These vulnerabilities are utilized by our vulnerability management tool InsightVM. The exploits are all included in the Metasploit framework and utilized by our penetration testing tool, Metasploit Pro. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 21 - 40 of 5,706 in total
GitLab Password Reset Account Takeover
Disclosed: January 11, 2024
module
Explore
Ivanti Connect Secure Unauthenticated Remote Code Execution
Disclosed: January 10, 2024
module
Explore
Cacti RCE via SQLi in pollers.php
Disclosed: December 20, 2023
module
Explore
MajorDoMo Command Injection
Disclosed: December 15, 2023
module
Explore
WordPress Backup Migration Plugin PHP Filter Chain RCE
Disclosed: December 11, 2023
module
Explore
GL.iNet Unauthenticated Remote Command Execution via the logread module.
Disclosed: December 10, 2023
module
Explore
Splunk Authenticated XSLT Upload RCE
Disclosed: November 28, 2023
module
Explore
WordPress Royal Elementor Addons RCE
Disclosed: November 23, 2023
module
Explore
ownCloud Phpinfo Reader
Disclosed: November 21, 2023
module
Explore
GitLens Git Local Configuration Exec
Disclosed: November 14, 2023
module
Explore
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
Disclosed: October 31, 2023
module
Explore
Apache ActiveMQ Unauthenticated Remote Code Execution
Disclosed: October 27, 2023
module
Explore
F5 BIG-IP TMUI AJP Smuggling RCE
Disclosed: October 26, 2023
module
Explore
Vinchin Backup and Recovery Command Injection
Disclosed: October 26, 2023
module
Explore
Mirth Connect Deserialization RCE
Disclosed: October 25, 2023
module
Explore
Citrix ADC (NetScaler) Bleed Scanner
Disclosed: October 25, 2023
module
Explore
Cisco IOX XE Unauthenticated RCE Chain
Disclosed: October 16, 2023
module
Explore
Cisco IOX XE unauthenticated OS command execution
Disclosed: October 16, 2023
module
Explore
Cisco IOX XE unauthenticated Command Line Interface (CLI) execution
Disclosed: October 16, 2023
module
Explore
Atlassian Confluence Data Center and Server Authentication Bypass via Broken Access Control
Disclosed: October 04, 2023
module
Explore