Vulnerability & Exploit Database

Try Surface Command Get a continuous 360° view of your attack surface

A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. The exploits are all included in the Metasploit framework. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 1,101 - 1,120 of 6,030 in total
JSON Swagger CodeGen Parameter Injector
Disclosed: June 23, 2016
module
Explore
SugarCRM REST Unserialize PHP Code Execution
Disclosed: June 23, 2016
module
Explore
phpMyAdmin Authenticated Remote Code Execution
Disclosed: June 23, 2016
module
Explore
NetBIOS Response "BadTunnel" Brute Force Spoof (NAT Tunnel)
Disclosed: June 14, 2016
module
Explore
ClamAV Remote Command Transmitter
Disclosed: June 08, 2016
module
Explore
Apache Shiro v1.2.4 Cookie RememberME Deserial RCE
Disclosed: June 07, 2016
module
Explore
Tiki-Wiki CMS Calendar Command Execution
Disclosed: June 06, 2016
module
Explore
Poison Ivy 2.1.x C2 Buffer Overflow
Disclosed: June 03, 2016
module
Explore
Linux Kernel 4.6.3 Netfilter Privilege Escalation
Disclosed: June 03, 2016
module
Explore
Apache Struts REST Plugin With Dynamic Method Invocation Remote Code Execution
Disclosed: June 01, 2016
module
Explore
ActiveMQ web shell upload
Disclosed: June 01, 2016
module
Explore
WordPress WP Mobile Detector 3.5 Shell Upload
Disclosed: May 31, 2016
module
Explore
Magento 2.0.6 Unserialize Remote Code Execution
Disclosed: May 17, 2016
module
Explore
Internet Explorer 11 VBScript Engine Memory Corruption
Disclosed: May 10, 2016
module
Explore
IPFire proxy.cgi RCE
Disclosed: May 04, 2016
module
Explore
Linux BPF doubleput UAF Privilege Escalation
Disclosed: May 04, 2016
module
Explore
WordPress Ninja Forms Unauthenticated File Upload
Disclosed: May 04, 2016
module
Explore
ImageMagick Delegate Arbitrary Command Execution
Disclosed: May 03, 2016
module
Explore
Allwinner 3.4 Legacy Kernel Local Privilege Escalation
Disclosed: April 30, 2016
module
Explore
Adobe Flash Player DeleteRangeTimelineOperation Type-Confusion
Disclosed: April 27, 2016
module
Explore