Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2026-21244
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2026-21248
Windows Hyper-V Remote Code Execution Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2017-7533
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-3842
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2025-47957
Microsoft Word Remote Code Execution Vulnerability |
HIGH | ExploitDB | 1% | — |
|
CVE-2016-3672
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2017-15918
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also… |
HIGH | ExploitDB | 1% | — |
|
CVE-2018-6084
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker… |
HIGH | ExploitDB | 1% | |
|
CVE-2018-15687
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2025-59254
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2026-21250
Windows HTTP.sys Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2018-13405
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-11599
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2025-49677
Microsoft Brokering File System Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2017-13216
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-3843
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2019-3844
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 1% | — |
|
CVE-2018-9445
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2025-47161
Microsoft Defender for Endpoint Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | — |
|
CVE-2019-1999
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2026-23231
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addcha… |
HIGH | ExploitDB | 1% | — |
|
CVE-2017-13209
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2025-49744
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2018-9515
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2020-0009
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-2000
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2025-37928
dm-bufio: don't schedule in atomic context |
HIGH | ExploitDB | 1% | — |
|
CVE-2025-49730
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2019-2025
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-2023
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 0% | |
|
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap c… |
MEDIUM | ExploitDB | 100% | |
|
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informati… |
MEDIUM | ExploitDB | 94% | |
|
CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password … |
MEDIUM | ExploitDB | 89% | — |
|
CVE-2019-11358
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 87% | — |
|
CVE-2018-0767
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information t… |
MEDIUM | ExploitDB | 65% | |
|
CVE-2026-32202
KEV Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
MEDIUM | ExploitDB | 64% | |
|
CVE-2019-5786
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bo… |
MEDIUM | ExploitDB | 62% | |
|
CVE-2018-0780
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain informa… |
MEDIUM | ExploitDB | 59% | |
|
CVE-2019-5825
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap co… |
MEDIUM | ExploitDB | 56% | |
|
CVE-2010-4052
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.… |
MEDIUM | ExploitDB | 51% | — |
|
CVE-2016-0168
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and … |
MEDIUM | ExploitDB | 43% | |
|
CVE-2016-0169
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and … |
MEDIUM | ExploitDB | 43% | |
|
CVE-2018-0833
Windows Denial of Service Vulnerability |
MEDIUM | ExploitDB | 40% | — |
|
CVE-2018-8474
Lync for Mac 2011 Security Feature Bypass Vulnerability |
MEDIUM | ExploitDB | 38% | — |
|
CVE-2018-6849
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such … |
MEDIUM | ExploitDB | 29% | |
|
CVE-2016-3388
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remo… |
MEDIUM | ExploitDB | 28% | |
|
CVE-2016-3216
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.… |
MEDIUM | ExploitDB | 25% | |
|
CVE-2018-8533
SQL Server Management Studio Information Disclosure Vulnerability |
MEDIUM | ExploitDB | 23% | — |
|
CVE-2017-8652
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information… |
MEDIUM | ExploitDB | 23% | |
|
CVE-2017-7308
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 18% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.