Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2021-44228
KEV Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio… |
CRITICAL | ExploitDB Nuclei | 100% | |
|
CVE-2010-3765
KEV Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMon… |
CRITICAL | ExploitDB | 83% | |
|
CVE-2019-11708
KEV Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the n… |
CRITICAL | ExploitDB | 56% | |
|
CVE-2018-20250
KEV In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE… |
HIGH | ExploitDB | 96% | |
|
CVE-2016-9079
KEV A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i… |
HIGH | ExploitDB | 87% | |
|
CVE-2016-7200
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 82% | |
|
CVE-2017-0037
KEV Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::Handle… |
HIGH | ExploitDB | 80% | |
|
CVE-2016-7201
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 80% | |
|
CVE-2013-1690
KEV Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do… |
HIGH | ExploitDB | 69% | |
|
CVE-2019-18426
KEV A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 all… |
HIGH | ExploitDB | 68% | |
|
CVE-2019-17026
KEV Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of … |
HIGH | ExploitDB | 47% | |
|
CVE-2019-11707
KEV A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an e… |
HIGH | ExploitDB | 38% | |
|
CVE-2026-2441
KEV Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbo… |
HIGH | ExploitDB | 22% | |
|
CVE-2025-2783
KEV Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remo… |
HIGH | ExploitDB | 9% | |
|
CVE-2009-3459
KEV Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attac… |
HIGH | ExploitDB | — |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.