Skip to content
Appaloosa Scout
Language selector
fr en

Public arsenal

Exploits

867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.

CVEs with exploit
867
Exploits catalogued
1,030
In CISA KEV
108
On tracked fleet
326
CVE Severity Apps
CVE-2026-21244

Windows Hyper-V Remote Code Execution Vulnerability

HIGH
CVE-2026-21248

Windows Hyper-V Remote Code Execution Vulnerability

HIGH
CVE-2017-7533

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2019-3842

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2025-47957

Microsoft Word Remote Code Execution Vulnerability

HIGH
CVE-2016-3672

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2017-15918

Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also…

HIGH
CVE-2018-6084

Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker…

HIGH
CVE-2018-15687

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2025-59254

Microsoft DWM Core Library Elevation of Privilege Vulnerability

HIGH
CVE-2026-21250

Windows HTTP.sys Elevation of Privilege Vulnerability

HIGH
CVE-2018-13405

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2019-11599

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2025-49677

Microsoft Brokering File System Elevation of Privilege Vulnerability

HIGH
CVE-2017-13216

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2019-3843

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2019-3844

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2018-9445

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2025-47161

Microsoft Defender for Endpoint Elevation of Privilege Vulnerability

HIGH
CVE-2019-1999

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2026-23231

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addcha…

HIGH
CVE-2017-13209

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2025-49744

Windows Graphics Component Elevation of Privilege Vulnerability

HIGH
CVE-2018-9515

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2020-0009

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2019-2000

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2025-37928

dm-bufio: don't schedule in atomic context

HIGH
CVE-2025-49730

Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability

HIGH
CVE-2019-2025

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2019-2023

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2020-16040

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap c…

MEDIUM
CVE-2017-5753

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informati…

MEDIUM
CVE-2016-6210

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password …

MEDIUM
CVE-2019-11358

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2018-0767

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information t…

MEDIUM
CVE-2026-32202 KEV

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

MEDIUM
CVE-2019-5786

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bo…

MEDIUM
CVE-2018-0780

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain informa…

MEDIUM
CVE-2019-5825

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap co…

MEDIUM
CVE-2010-4052

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.…

MEDIUM
CVE-2016-0168

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

MEDIUM
CVE-2016-0169

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

MEDIUM
CVE-2018-0833

Windows Denial of Service Vulnerability

MEDIUM
CVE-2018-8474

Lync for Mac 2011 Security Feature Bypass Vulnerability

MEDIUM
CVE-2018-6849

In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such …

MEDIUM
CVE-2016-3388

Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remo…

MEDIUM
CVE-2016-3216

GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.…

MEDIUM
CVE-2018-8533

SQL Server Management Studio Information Disclosure Vulnerability

MEDIUM
CVE-2017-8652

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information…

MEDIUM
CVE-2017-7308

Indexed via Android Security Bulletin — full NVD metadata pending.

MEDIUM

Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.