A curated repository of vetted computer software exploits and exploitable vulnerabilities.

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review. These vulnerabilities are utilized by our vulnerability management tool InsightVM. The exploits are all included in the Metasploit framework and utilized by our penetration testing tool, Metasploit Pro. Our vulnerability and exploit database is updated frequently and contains the most recent security research.

Results 01 - 20 of 5,785 in total
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
Disclosed: 9月 11, 2024
module
Explore
VICIdial Authenticated Remote Code Execution
Disclosed: 9月 10, 2024
module
Explore
Vicidial SQL Injection Time-based Admin Credentials Enumeration
Disclosed: 9月 10, 2024
module
Explore
SPIP BigUp Plugin Unauthenticated RCE
Disclosed: 9月 06, 2024
module
Explore
Wordpress LiteSpeed Cache plugin cookie theft
Disclosed: 9月 04, 2024
module
Explore
WhatsUp Gold SQL Injection (CVE-2024-6670)
Disclosed: 8月 29, 2024
module
Explore
GiveWP Unauthenticated Donation Process Exploit
Disclosed: 8月 25, 2024
module
Explore
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
Disclosed: 8月 23, 2024
module
Explore
SPIP Unauthenticated RCE via porte_plume Plugin
Disclosed: 8月 16, 2024
module
Explore
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
Disclosed: 8月 15, 2024
module
Explore
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
Disclosed: 8月 05, 2024
module
Explore
Calibre Python Code Injection (CVE-2024-6782)
Disclosed: 7月 31, 2024
module
Explore
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
Disclosed: 7月 26, 2024
module
Explore
Acronis Cyber Infrastructure default password remote code execution
Disclosed: 7月 24, 2024
module
Explore
Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419)
Disclosed: 7月 20, 2024
module
Explore
Geoserver unauthenticated Remote Code Execution
Disclosed: 7月 01, 2024
module
Explore
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
Disclosed: 6月 25, 2024
module
Explore
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
Disclosed: 6月 25, 2024
module
Explore
Magento XXE Unserialize Arbitrary File Read
Disclosed: 6月 11, 2024
module
Explore
Windows Kernel Time of Check Time of Use LPE in AuthzBasepCopyoutInternalSecurityAttributes
Disclosed: 6月 11, 2024
module
Explore