Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2021-44228
KEV Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio… |
CRITICAL | ExploitDB Nuclei | 100% | 1 |
|
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, a… |
CRITICAL | ExploitDB | 100% | 2 |
|
CVE-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X … |
CRITICAL | ExploitDB | 96% | 1 |
|
CVE-2015-0311
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS … |
CRITICAL | ExploitDB | 86% | 1 |
|
CVE-2014-1511
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attack… |
CRITICAL | ExploitDB | 84% | 2 |
|
CVE-2010-3765
KEV Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMon… |
CRITICAL | ExploitDB | 83% | 2 |
|
CVE-2014-1510
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey b… |
CRITICAL | ExploitDB | 82% | 2 |
|
CVE-2019-11708
KEV Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the n… |
CRITICAL | ExploitDB | 56% | 2 |
|
CVE-2010-1205
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow re… |
CRITICAL | ExploitDB | 43% | 7 |
|
CVE-2017-5375
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulne… |
CRITICAL | ExploitDB | 34% | 2 |
|
CVE-2014-4650
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separator… |
CRITICAL | ExploitDB | 25% | 3 |
|
CVE-2016-9899
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vul… |
CRITICAL | ExploitDB | 21% | 2 |
|
CVE-2018-5159
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resultin… |
CRITICAL | ExploitDB | 21% | 2 |
|
CVE-2019-9791
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compi… |
CRITICAL | ExploitDB | 20% | 2 |
|
CVE-2017-5465
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inac… |
CRITICAL | ExploitDB | 19% | 2 |
|
CVE-2017-5447
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash a… |
CRITICAL | ExploitDB | 17% | 2 |
|
CVE-2017-5404
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node… |
CRITICAL | ExploitDB | 17% | 2 |
|
CVE-2019-9792
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailou… |
CRITICAL | ExploitDB | 13% | 2 |
|
CVE-2019-11703
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain emai… |
CRITICAL | ExploitDB | 11% | 1 |
|
CVE-2019-11704
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing cer… |
CRITICAL | ExploitDB | 11% | 1 |
|
CVE-2019-11705
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain… |
CRITICAL | ExploitDB | 10% | 1 |
|
CVE-2008-0081
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted… |
CRITICAL | ExploitDB | — | 3 |
|
CVE-2011-0611
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR … |
HIGH | ExploitDB | 99% | 4 |
|
CVE-2018-20250
KEV In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE… |
HIGH | ExploitDB | 96% | 1 |
|
CVE-2016-9079
KEV A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i… |
HIGH | ExploitDB | 87% | 2 |
|
CVE-2018-17463
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code… |
HIGH | ExploitDB | 85% | 2 |
|
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 83% | 1 |
|
CVE-2016-7200
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 82% | 1 |
|
CVE-2018-0758
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 81% | 1 |
|
CVE-2017-0037
KEV Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::Handle… |
HIGH | ExploitDB | 80% | 1 |
|
CVE-2019-0567
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 80% | 1 |
|
CVE-2016-7201
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 80% | 1 |
|
CVE-2018-0769
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 79% | 1 |
|
CVE-2020-6418
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via… |
HIGH | ExploitDB | 79% | 2 |
|
CVE-2017-0070
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memo… |
HIGH | ExploitDB | 79% | 1 |
|
CVE-2018-0770
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 78% | 1 |
|
CVE-2018-0776
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 78% | 1 |
|
CVE-2018-0777
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 78% | 1 |
|
CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result … |
HIGH | ExploitDB | 78% | 1 |
|
CVE-2016-7202
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary … |
HIGH | ExploitDB | 73% | 1 |
|
CVE-2019-13720
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruptio… |
HIGH | ExploitDB | 73% | 2 |
|
CVE-2017-8729
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due … |
HIGH | ExploitDB | 72% | 1 |
|
CVE-2017-8740
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due … |
HIGH | ExploitDB | 72% | 1 |
|
CVE-2017-8636
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 an… |
HIGH | ExploitDB | 72% | 1 |
|
CVE-2017-8641
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 an… |
HIGH | ExploitDB | 72% | 1 |
|
CVE-2016-7241
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (… |
HIGH | ExploitDB | 71% | 1 |
|
CVE-2016-3247
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (… |
HIGH | ExploitDB | 71% | 1 |
|
CVE-2017-8755
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in … |
HIGH | ExploitDB | 71% | 1 |
|
CVE-2018-8279
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memor… |
HIGH | ExploitDB | 71% | 1 |
|
CVE-2018-8229
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 71% | 1 |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.