Skip to content
Appaloosa Scout
Language selector
fr en

Public arsenal

Exploits

867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.

CVEs with exploit
867
Exploits catalogued
1,030
In CISA KEV
107
On tracked fleet
326
CVE Severity Apps
CVE-2019-0708 KEV

Remote Desktop Services Remote Code Execution Vulnerability

CRITICAL
CVE-2021-44228 KEV

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio…

CRITICAL
CVE-2025-53770 KEV

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over…

CRITICAL
CVE-2021-26855 KEV

Microsoft Exchange Server Remote Code Execution Vulnerability

CRITICAL
CVE-2024-4577 KEV

Argument Injection in PHP-CGI

CRITICAL
CVE-2017-0199 KEV

Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows

CRITICAL
CVE-2019-0604 KEV

Microsoft SharePoint Remote Code Execution Vulnerability

CRITICAL
CVE-2020-0796 KEV

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles ce…

CRITICAL
CVE-2020-1472 KEV

Netlogon Elevation of Privilege Vulnerability

CRITICAL
CVE-2017-0148 KEV

Windows SMB Remote Code Execution Vulnerability

CRITICAL
CVE-2020-0646 KEV

.NET Framework Remote Code Execution Injection Vulnerability

CRITICAL
CVE-2020-1147 KEV

.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability

CRITICAL
CVE-2017-0143 KEV

Windows SMB Remote Code Execution Vulnerability

CRITICAL
CVE-2017-8464 KEV

LNK Remote Code Execution Vulnerability

CRITICAL
CVE-2017-0146 KEV

Windows SMB Remote Code Execution Vulnerability

CRITICAL
CVE-2020-0674 KEV

Scripting Engine Memory Corruption Vulnerability

CRITICAL
CVE-2016-5195 KEV

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2010-3765 KEV

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMon…

CRITICAL
CVE-2018-8298 KEV

Scripting Engine Memory Corruption Vulnerability

CRITICAL
CVE-2019-1429 KEV

Scripting Engine Memory Corruption Vulnerability

CRITICAL
CVE-2017-8540 KEV

Microsoft Malware Protection Engine Remote Code Execution Vulnerability

CRITICAL
CVE-2025-32463 KEV

Sudo before 1.9.17p1 allows local users to obtain root access

CRITICAL
CVE-2019-11708 KEV

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the n…

CRITICAL
CVE-2025-24085 KEV

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.…

CRITICAL
CVE-2023-44487 KEV

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams …

HIGH
CVE-2021-41773 KEV

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

HIGH
CVE-2020-0688 KEV

Microsoft Exchange Validation Key Remote Code Execution Vulnerability

HIGH
CVE-2017-11882 KEV

Microsoft Office Memory Corruption Vulnerability

HIGH
CVE-2021-27065 KEV

Microsoft Exchange Server Remote Code Execution Vulnerability

HIGH
CVE-2017-0147 KEV

Windows SMB Information Disclosure Vulnerability

HIGH
CVE-2017-0144 KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

HIGH
CVE-2020-0618 KEV

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests…

HIGH
CVE-2018-20250 KEV

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE…

HIGH
CVE-2021-4034 KEV

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed…

HIGH
CVE-2016-0189 KEV

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products,…

HIGH
CVE-2017-8570 KEV

Microsoft Office Remote Code Execution Vulnerability

HIGH
CVE-2017-0145 KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

HIGH
CVE-2022-0847 KEV

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2020-0601 KEV

Windows CryptoAPI Spoofing Vulnerability

HIGH
CVE-2017-8759 KEV

.NET Framework Remote Code Execution Vulnerability

HIGH
CVE-2018-8174 KEV

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript…

HIGH
CVE-2016-9079 KEV

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i…

HIGH
CVE-2017-0213 KEV

Windows COM Elevation of Privilege Vulnerability

HIGH
CVE-2016-7200 KEV

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s…

HIGH
CVE-2019-0752 KEV

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer,…

HIGH
CVE-2023-4911 KEV

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2016-7255 KEV

Win32k Elevation of Privilege Vulnerability

HIGH
CVE-2025-33073 KEV

Windows SMB Client Elevation of Privilege Vulnerability

HIGH
CVE-2017-0037 KEV

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::Handle…

HIGH
CVE-2016-7201 KEV

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s…

HIGH

Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.