Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2019-0708
KEV Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2021-34473
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2021-40438
KEV A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue … |
CRITICAL | Nuclei | 100% | — |
|
CVE-2021-44228
KEV Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio… |
CRITICAL | ExploitDB Nuclei | 100% | 1 |
|
CVE-2025-53770
KEV Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over… |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2021-26855
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2024-4577
KEV Argument Injection in PHP-CGI |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2023-29357
KEV Microsoft SharePoint Server Elevation of Privilege Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2025-59287
KEV Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2017-0199
KEV Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2021-38647
KEV Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2019-0604
KEV Microsoft SharePoint Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2020-0796
KEV A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles ce… |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2020-1472
KEV Netlogon Elevation of Privilege Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2017-0148
KEV Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 99% | — |
|
CVE-2020-0646
KEV .NET Framework Remote Code Execution Injection Vulnerability |
CRITICAL | ExploitDB | 99% | — |
|
CVE-2019-5544
KEV Microsoft Security Update Guide entry — NVD enrichira. |
CRITICAL | Nuclei | 97% | — |
|
CVE-2020-1147
KEV .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 94% | — |
|
CVE-2017-0143
KEV Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 93% | — |
|
CVE-2025-12480
KEV Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup… |
CRITICAL | Nuclei | 91% | — |
|
CVE-2017-8464
KEV LNK Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 90% | — |
|
CVE-2017-0146
KEV Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 90% | — |
|
CVE-2020-0674
KEV Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 87% | — |
|
CVE-2016-5195
KEV Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 84% | — |
|
CVE-2010-3765
KEV Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMon… |
CRITICAL | ExploitDB | 83% | 2 |
|
CVE-2018-8298
KEV Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 75% | — |
|
CVE-2019-1429
KEV Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 73% | — |
|
CVE-2017-8540
KEV Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 72% | — |
|
CVE-2025-32463
KEV Sudo before 1.9.17p1 allows local users to obtain root access |
CRITICAL | ExploitDB | 59% | — |
|
CVE-2019-11708
KEV Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the n… |
CRITICAL | ExploitDB | 56% | 2 |
|
CVE-2025-14611
KEV Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cry… |
CRITICAL | Nuclei | 53% | — |
|
CVE-2026-55040
KEV Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. |
CRITICAL | Nuclei | 40% | — |
|
CVE-2025-24085
KEV A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.… |
CRITICAL | ExploitDB | 18% | — |
|
CVE-2026-58644
KEV Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
CRITICAL | Nuclei | 16% | — |
|
CVE-2023-44487
KEV The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams … |
HIGH | ExploitDB | 100% | — |
|
CVE-2021-41773
KEV Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
HIGH | ExploitDB Nuclei | 100% | — |
|
CVE-2020-0688
KEV Microsoft Exchange Validation Key Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-11882
KEV Microsoft Office Memory Corruption Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2021-27065
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-0147
KEV Windows SMB Information Disclosure Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-0144
KEV The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 99% | — |
|
CVE-2020-0618
KEV A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests… |
HIGH | ExploitDB Nuclei | 99% | — |
|
CVE-2024-29059
KEV .NET Framework Information Disclosure Vulnerability |
HIGH | Nuclei | 99% | — |
|
CVE-2021-33766
KEV Microsoft Exchange Server Information Disclosure Vulnerability |
HIGH | Nuclei | 98% | — |
|
CVE-2018-20250
KEV In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE… |
HIGH | ExploitDB | 96% | 1 |
|
CVE-2021-4034
KEV A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed… |
HIGH | ExploitDB | 95% | — |
|
CVE-2016-0189
KEV The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products,… |
HIGH | ExploitDB | 94% | — |
|
CVE-2025-11371
KEV In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusi… |
HIGH | Nuclei | 92% | — |
|
CVE-2023-41763
KEV Skype for Business Elevation of Privilege Vulnerability |
HIGH | Nuclei | 90% | — |
|
CVE-2017-8570
KEV Microsoft Office Remote Code Execution Vulnerability |
HIGH | ExploitDB | 90% | — |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.