Vulnerability & Exploit Database

A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. These vulnerabilities are utilized by our vulnerability management tool InsightVM. The exploits are all included in the Metasploit framework and utilized by our penetration testing tool, Metasploit Pro. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 321 - 340 of 5,708 in total
Windows Server 2012 SrClient DLL hijacking
Disclosed: February 19, 2021
module
Explore
Microsoft Windows SMB Direct Session Takeover
Disclosed: February 16, 2021
module
Explore
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
Disclosed: February 13, 2021
module
Explore
Win32k ConsoleControl Offset Confusion
Disclosed: February 10, 2021
module
Explore
Win32k ConsoleControl Offset Confusion
Disclosed: February 09, 2021
module
Explore
Advantech iView Unauthenticated Remote Code Execution
Disclosed: February 09, 2021
module
Explore
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
Disclosed: February 09, 2021
module
Explore
NetMotion Mobility Server MvcUtil Java Deserialization
Disclosed: February 08, 2021
module
Explore
Wordpress Plugin Modern Events Calendar - Authenticated Remote Code Execution
Disclosed: January 29, 2021
module
Explore
Sudo Heap-Based Buffer Overflow
Disclosed: January 26, 2021
module
Explore
Apache Druid 0.20.0 Remote Command Execution
Disclosed: January 21, 2021
module
Explore
Lucee Administrator imgProcess.cfm Arbitrary File Write
Disclosed: January 15, 2021
module
Explore
Unauthenticated remote code execution in Ignition
Disclosed: January 13, 2021
module
Explore
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
Disclosed: January 12, 2021
module
Explore
Apache Flink JobManager Traversal
Disclosed: January 05, 2021
module
Explore
Klog Server authenticate.php user Unauthenticated Command Injection
Disclosed: December 27, 2020
module
Explore
Microsoft RDP Web Client Login Enumeration
Disclosed: December 23, 2020
module
Explore
Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection
Disclosed: December 19, 2020
module
Explore
HPE Systems Insight Manager AMF Deserialization RCE
Disclosed: December 15, 2020
module
Explore
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
Disclosed: December 12, 2020
module
Explore