Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2019-0708
KEV Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2021-34473
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2021-40438
KEV A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue … |
CRITICAL | Nuclei | 100% | — |
|
CVE-2021-44228
KEV Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio… |
CRITICAL | ExploitDB Nuclei | 100% | 1 |
|
CVE-2025-53770
KEV Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over… |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2021-26855
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2024-4577
KEV Argument Injection in PHP-CGI |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2023-29357
KEV Microsoft SharePoint Server Elevation of Privilege Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2025-59287
KEV Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2017-0199
KEV Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2021-38647
KEV Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2019-0604
KEV Microsoft SharePoint Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, a… |
CRITICAL | ExploitDB | 100% | 2 |
|
CVE-2020-0796
KEV A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles ce… |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2025-1974
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod … |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2020-1472
KEV Netlogon Elevation of Privilege Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2017-0148
KEV Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 99% | — |
|
CVE-2020-0646
KEV .NET Framework Remote Code Execution Injection Vulnerability |
CRITICAL | ExploitDB | 99% | — |
|
CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19… |
CRITICAL | ExploitDB | 97% | — |
|
CVE-2019-5544
KEV Microsoft Security Update Guide entry — NVD enrichira. |
CRITICAL | Nuclei | 97% | — |
|
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier |
CRITICAL | ExploitDB | 97% | — |
|
CVE-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X … |
CRITICAL | ExploitDB | 96% | 1 |
|
CVE-2020-1147
KEV .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 94% | — |
|
CVE-2017-0143
KEV Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 93% | — |
|
CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 93% | — |
|
CVE-2025-12480
KEV Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup… |
CRITICAL | Nuclei | 91% | — |
|
CVE-2020-11984
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
CRITICAL | Nuclei | 90% | — |
|
CVE-2017-8464
KEV LNK Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 90% | — |
|
CVE-2017-0146
KEV Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 90% | — |
|
CVE-2020-0674
KEV Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 87% | — |
|
CVE-2025-49844
Redis Lua Use-After-Free may lead to remote code execution |
CRITICAL | Nuclei | 87% | — |
|
CVE-2015-0311
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS … |
CRITICAL | ExploitDB | 86% | 1 |
|
CVE-2014-1511
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attack… |
CRITICAL | ExploitDB | 84% | 2 |
|
CVE-2016-5195
KEV Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 84% | — |
|
CVE-2010-3765
KEV Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMon… |
CRITICAL | ExploitDB | 83% | 2 |
|
CVE-2014-1510
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey b… |
CRITICAL | ExploitDB | 82% | 2 |
|
CVE-2017-0290
Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 82% | — |
|
CVE-2020-13160
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. |
CRITICAL | ExploitDB | 81% | — |
|
CVE-2020-0609
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 75% | — |
|
CVE-2018-8298
KEV Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 75% | — |
|
CVE-2019-1429
KEV Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 73% | — |
|
CVE-2017-8540
KEV Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 72% | — |
|
CVE-2021-28480
Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 71% | — |
|
CVE-2020-16952
Microsoft SharePoint Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 71% | — |
|
CVE-2018-8631
Internet Explorer Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 68% | — |
|
CVE-2020-0610
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 68% | — |
|
CVE-2017-11907
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 65% | — |
|
CVE-2017-9417
Broadcom BCM43xx Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 64% | — |
|
CVE-2018-0986
Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 63% | — |
|
CVE-2025-62168
Squid vulnerable to information disclosure via authentication credential leakage in error handling |
CRITICAL | Nuclei | 63% | — |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.