Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2025-49744
Windows Graphics Component Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2018-9515
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2020-0009
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-2000
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2025-37928
dm-bufio: don't schedule in atomic context |
HIGH | ExploitDB | 1% | — |
|
CVE-2025-49730
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 1% | |
|
CVE-2019-2025
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 1% | |
|
CVE-2019-2023
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 0% | |
|
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap c… |
MEDIUM | ExploitDB | 100% | |
|
CVE-2025-49706
KEV Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
MEDIUM | Nuclei | 99% | — |
|
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informati… |
MEDIUM | ExploitDB | 94% | |
|
CVE-2021-41349
Microsoft Exchange Server Spoofing Vulnerability |
MEDIUM | Nuclei | 93% | — |
|
CVE-2023-48795
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | Nuclei | 93% | |
|
CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password … |
MEDIUM | ExploitDB | 89% | — |
|
CVE-2019-11358
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 87% | — |
|
CVE-2018-0767
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information t… |
MEDIUM | ExploitDB | 65% | |
|
CVE-2026-32202
KEV Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
MEDIUM | ExploitDB | 64% | |
|
CVE-2019-5786
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bo… |
MEDIUM | ExploitDB | 62% | |
|
CVE-2018-0780
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain informa… |
MEDIUM | ExploitDB | 59% | |
|
CVE-2019-5825
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap co… |
MEDIUM | ExploitDB | 56% | |
|
CVE-2010-4052
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.… |
MEDIUM | ExploitDB | 51% | — |
|
CVE-2016-0168
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and … |
MEDIUM | ExploitDB | 43% | |
|
CVE-2016-0169
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and … |
MEDIUM | ExploitDB | 43% | |
|
CVE-2018-0833
Windows Denial of Service Vulnerability |
MEDIUM | ExploitDB | 40% | — |
|
CVE-2018-8474
Lync for Mac 2011 Security Feature Bypass Vulnerability |
MEDIUM | ExploitDB | 38% | — |
|
CVE-2018-6849
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such … |
MEDIUM | ExploitDB | 29% | |
|
CVE-2016-3388
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remo… |
MEDIUM | ExploitDB | 28% | |
|
CVE-2016-3216
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.… |
MEDIUM | ExploitDB | 25% | |
|
CVE-2018-8533
SQL Server Management Studio Information Disclosure Vulnerability |
MEDIUM | ExploitDB | 23% | — |
|
CVE-2017-8652
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information… |
MEDIUM | ExploitDB | 23% | |
|
CVE-2021-29622
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | Nuclei | 20% | — |
|
CVE-2017-7308
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 18% | |
|
CVE-2017-8644
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information… |
MEDIUM | ExploitDB | 15% | |
|
CVE-2016-0772
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when… |
MEDIUM | ExploitDB | 15% | |
|
CVE-2018-0891
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Win… |
MEDIUM | ExploitDB | 14% | |
|
CVE-2019-0948
Windows Event Viewer Information Disclosure Vulnerability |
MEDIUM | ExploitDB | 13% | |
|
CVE-2017-0785
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 12% | |
|
CVE-2020-6519
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a cra… |
MEDIUM | ExploitDB | 11% | |
|
CVE-2019-0612
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By … |
MEDIUM | ExploitDB | 11% | |
|
CVE-2012-6708
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 9% | — |
|
CVE-2013-5123
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allow… |
MEDIUM | ExploitDB | 8% | — |
|
CVE-2018-13042
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebit… |
MEDIUM | ExploitDB | 8% | |
|
CVE-2016-1839
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 7% | |
|
CVE-2019-9816
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing fo… |
MEDIUM | ExploitDB | 6% | |
|
CVE-2017-5124
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary… |
MEDIUM | ExploitDB | 5% | |
|
CVE-2017-2480
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2… |
MEDIUM | ExploitDB | 4% | |
|
CVE-2017-11548
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service |
MEDIUM | ExploitDB | 4% | — |
|
CVE-2026-33829
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform sp… |
MEDIUM | ExploitDB | 3% | |
|
CVE-2018-5407
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 3% | — |
|
CVE-2018-6130
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially … |
MEDIUM | ExploitDB | 3% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.