Skip to content
Appaloosa Scout
Language selector
fr en

Public arsenal

Exploits

867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.

CVEs with exploit
867
Exploits catalogued
1,030
In CISA KEV
108
On tracked fleet
326
CVE Severity Apps
CVE-2025-49744

Windows Graphics Component Elevation of Privilege Vulnerability

HIGH
CVE-2018-9515

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2020-0009

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2019-2000

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2025-37928

dm-bufio: don't schedule in atomic context

HIGH
CVE-2025-49730

Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability

HIGH
CVE-2019-2025

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2019-2023

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2020-16040

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap c…

MEDIUM
CVE-2025-49706 KEV

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

MEDIUM
CVE-2017-5753

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informati…

MEDIUM
CVE-2021-41349

Microsoft Exchange Server Spoofing Vulnerability

MEDIUM
CVE-2023-48795

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2016-6210

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password …

MEDIUM
CVE-2019-11358

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2018-0767

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information t…

MEDIUM
CVE-2026-32202 KEV

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

MEDIUM
CVE-2019-5786

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bo…

MEDIUM
CVE-2018-0780

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain informa…

MEDIUM
CVE-2019-5825

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap co…

MEDIUM
CVE-2010-4052

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.…

MEDIUM
CVE-2016-0168

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

MEDIUM
CVE-2016-0169

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

MEDIUM
CVE-2018-0833

Windows Denial of Service Vulnerability

MEDIUM
CVE-2018-8474

Lync for Mac 2011 Security Feature Bypass Vulnerability

MEDIUM
CVE-2018-6849

In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such …

MEDIUM
CVE-2016-3388

Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remo…

MEDIUM
CVE-2016-3216

GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.…

MEDIUM
CVE-2018-8533

SQL Server Management Studio Information Disclosure Vulnerability

MEDIUM
CVE-2017-8652

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information…

MEDIUM
CVE-2021-29622

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2017-7308

Indexed via Android Security Bulletin — full NVD metadata pending.

MEDIUM
CVE-2017-8644

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information…

MEDIUM
CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when…

MEDIUM
CVE-2018-0891

ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Win…

MEDIUM
CVE-2019-0948

Windows Event Viewer Information Disclosure Vulnerability

MEDIUM
CVE-2017-0785

Indexed via Android Security Bulletin — full NVD metadata pending.

MEDIUM
CVE-2020-6519

Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a cra…

MEDIUM
CVE-2019-0612

A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By …

MEDIUM
CVE-2012-6708

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2013-5123

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allow…

MEDIUM
CVE-2018-13042

The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebit…

MEDIUM
CVE-2016-1839

Indexed via Android Security Bulletin — full NVD metadata pending.

MEDIUM
CVE-2019-9816

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing fo…

MEDIUM
CVE-2017-5124

Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary…

MEDIUM
CVE-2017-2480

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2…

MEDIUM
CVE-2017-11548

The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service

MEDIUM
CVE-2026-33829

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform sp…

MEDIUM
CVE-2018-5407

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2018-6130

Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially …

MEDIUM

Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.