Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2017-11823
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
HIGH | ExploitDB | 3% | |
|
CVE-2019-0552
Windows COM Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 3% | |
|
CVE-2017-0412
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 3% | |
|
CVE-2023-23399
Microsoft Excel Remote Code Execution Vulnerability |
HIGH | ExploitDB | 3% | |
|
CVE-2019-1170
Windows NTFS Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2025-27751
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
HIGH | ExploitDB | 2% | |
|
CVE-2019-0943
Windows ALPC Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2018-0901
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2018-0832
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2018-0894
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2018-0897
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2018-0966
Device Guard Security Feature Bypass Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2018-0821
Windows AppContainer Elevation Of Privilege Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2018-15686
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 2% | — |
|
CVE-2025-47175
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
HIGH | ExploitDB | 2% | |
|
CVE-2024-12905
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory… |
HIGH | ExploitDB | 2% | — |
|
CVE-2023-33148
Microsoft Office Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 2% | — |
|
CVE-2025-47165
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
HIGH | ExploitDB | 2% | |
|
CVE-2026-57219
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint ca… |
HIGH | Nuclei | 2% | — |
|
CVE-2016-2494
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 2% | |
|
CVE-2025-49683
Microsoft Virtual Hard Disk Remote Code Execution Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2019-10529
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 2% | |
|
CVE-2025-47987
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 2% | |
|
CVE-2016-9793
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 2% | |
|
CVE-2018-10906
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2016-1583
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-10038
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as … |
HIGH | ExploitDB | 1% | |
|
CVE-2017-9150
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2026-21244
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2026-21248
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2017-7533
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-3842
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2025-47957
Microsoft Word Remote Code Execution Vulnerability |
HIGH | ExploitDB | 1% | — |
|
CVE-2016-3672
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2017-15918
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also… |
HIGH | ExploitDB | 1% | — |
|
CVE-2018-6084
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker… |
HIGH | ExploitDB | 1% | |
|
CVE-2018-15687
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2025-59254
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2026-21250
Windows HTTP.sys Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2018-13405
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-11599
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2025-49677
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2017-13216
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-3843
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2019-3844
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2018-9445
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2025-47161
Microsoft Defender for Endpoint Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | — |
|
CVE-2019-1999
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2026-23231
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addcha… |
HIGH | ExploitDB | 1% | — |
|
CVE-2017-13209
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.