[MSF] Metasploit Modules

13 CVEs with a Metasploit Framework exploit module

These vulnerabilities have a working Metasploit Framework module from Rapid7's metasploit-framework repo. An MSF module means point-and-click exploitation: attackers and red teams already use it. Patch immediately.

CVE-2026-31431

Apr 22, 2026

High (7.8)

Copy Fail (CVE-2026-31431) is an in-place AEAD memory bug in the Linux kernel's algif_aead crypto interface, allowing local low-privileged attackers to corrupt memory and execute arbitrary code at kernel level. The fix reverts commit 72548b093ee3 (except for associated-data copying) to restore out-of-place operation. Disclosed by Theori/Xint as Copy Fail; actively exploited in the wild and listed in CISA KEV.

Read Advisory

CVE-2026-28501

Mar 6, 2026

Critical (9.8)

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components...

Read Advisory

CVE-2026-28289

Mar 3, 2026

Critical (10.0)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with f...

Read Advisory

CVE-2026-20127

Feb 25, 2026

Critical (10.0)

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, r...

Read Advisory

CVE-2026-27174

Feb 18, 2026

Critical (9.8)

MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to contin...

Read Advisory

CVE-2026-27175

Feb 18, 2026

Critical (9.8)

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into a command string within double qu...

Read Advisory

CVE-2026-27180

Feb 18, 2026

Critical (9.8)

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module exposes its admin() method...

Read Advisory

CVE-2024-1708

Feb 21, 2024

High (8.4)

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critic...

Read Advisory

CVE-2022-0492

Mar 3, 2022

High (7.8)

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_a...

Read Advisory

CVE-2010-0806

Mar 10, 2010

Critical (9.3)

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving acce...

Read Advisory

CVE-2010-0249

Jan 15, 2010

Critical (9.3)

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 20...

Read Advisory

CVE-2009-3459

Oct 13, 2009

Critical (9.3)

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers mem...

Read Advisory

CVE-2008-4250

Oct 23, 2008

Critical (10.0)

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a craft...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.