A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. These vulnerabilities are utilized by our vulnerability management tool InsightVM. The exploits are all included in the Metasploit framework and utilized by our penetration testing tool, Metasploit Pro. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 01 - 20 of 5,766 in total
GiveWP Unauthenticated Donation Process Exploit
Disclosed: August 25, 2024
module
Explore
SPIP Unauthenticated RCE via porte_plume Plugin
Disclosed: August 16, 2024
module
Explore
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
Disclosed: August 05, 2024
module
Explore
Calibre Python Code Injection (CVE-2024-6782)
Disclosed: July 31, 2024
module
Explore
Geoserver unauthenticated Remote Code Execution
Disclosed: July 01, 2024
module
Explore
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
Disclosed: June 25, 2024
module
Explore
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
Disclosed: June 25, 2024
module
Explore
Magento XXE Unserialize Arbitrary File Read
Disclosed: June 11, 2024
module
Explore
PHP CGI Argument Injection Remote Code Execution
Disclosed: June 06, 2024
module
Explore
Telerik Report Server Auth Bypass and Deserialization RCE
Disclosed: June 04, 2024
module
Explore
Telerik Report Server Auth Bypass
Disclosed: June 04, 2024
module
Explore
Apache OFBiz forgotPassword/ProgramExport RCE
Disclosed: May 30, 2024
module
Explore
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
Disclosed: May 25, 2024
module
Explore
Ivanti EPM RecordGoodApp SQLi RCE
Disclosed: May 24, 2024
module
Explore
WordPress Hash Form Plugin RCE
Disclosed: May 23, 2024
module
Explore
Atlassian Confluence Administrator Code Macro Remote Code Execution
Disclosed: May 21, 2024
module
Explore
Cacti Import Packages RCE
Disclosed: May 12, 2024
module
Explore
DIAEnergie SQL Injection (CVE-2024-4548)
Disclosed: May 06, 2024
module
Explore
Flowmon Unauthenticated Command Injection
Disclosed: April 23, 2024
module
Explore
Apache HugeGraph Gremlin RCE
Disclosed: April 22, 2024
module
Explore