Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2017-8644
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information… |
MEDIUM | ExploitDB | 15% | |
|
CVE-2016-0772
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when… |
MEDIUM | ExploitDB | 15% | |
|
CVE-2018-0891
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Win… |
MEDIUM | ExploitDB | 14% | |
|
CVE-2019-0948
Windows Event Viewer Information Disclosure Vulnerability |
MEDIUM | ExploitDB | 13% | |
|
CVE-2017-0785
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 12% | |
|
CVE-2020-6519
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a cra… |
MEDIUM | ExploitDB | 11% | |
|
CVE-2019-0612
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By … |
MEDIUM | ExploitDB | 11% | |
|
CVE-2012-6708
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 9% | — |
|
CVE-2013-5123
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allow… |
MEDIUM | ExploitDB | 8% | — |
|
CVE-2018-13042
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebit… |
MEDIUM | ExploitDB | 8% | |
|
CVE-2016-1839
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 7% | |
|
CVE-2019-9816
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing fo… |
MEDIUM | ExploitDB | 6% | |
|
CVE-2017-5124
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary… |
MEDIUM | ExploitDB | 5% | |
|
CVE-2017-2480
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2… |
MEDIUM | ExploitDB | 4% | |
|
CVE-2017-11548
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service |
MEDIUM | ExploitDB | 4% | — |
|
CVE-2026-33829
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform sp… |
MEDIUM | ExploitDB | 3% | |
|
CVE-2018-5407
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 3% | — |
|
CVE-2018-6130
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially … |
MEDIUM | ExploitDB | 3% | |
|
CVE-2016-6772
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 3% | |
|
CVE-2018-6129
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out … |
MEDIUM | ExploitDB | 3% | |
|
CVE-2016-6689
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 2% | |
|
CVE-2016-4486
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 2% | |
|
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. |
MEDIUM | ExploitDB | 2% | |
|
CVE-2023-1998
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 1% | — |
|
CVE-2026-58058
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/… |
MEDIUM | ExploitDB | 1% | — |
|
CVE-2016-4578
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 1% | |
|
CVE-2014-1739
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 1% | |
|
CVE-2017-13236
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 1% | |
|
CVE-2023-24626
socket.c in GNU Screen through 4.9.0 when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD) al… |
MEDIUM | ExploitDB | 1% | — |
|
CVE-2018-9488
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 0% | |
|
CVE-2016-3325
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, … |
LOW | ExploitDB | 54% | |
|
CVE-2019-15126
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (r… |
LOW | ExploitDB | 7% | — |
|
CVE-2025-32462
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed… |
LOW | ExploitDB | 4% | |
|
CVE-2004-2687
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers t… |
— | ExploitDB Nuclei | 88% | |
|
CVE-2011-2371
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.1… |
— | ExploitDB | 76% | |
|
CVE-2013-0758
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 1… |
— | ExploitDB | 73% | |
|
CVE-2004-0204
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 1… |
— | ExploitDB | 72% | |
|
CVE-2006-0295
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to e… |
— | ExploitDB | 71% | |
|
CVE-2011-0105
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value … |
— | ExploitDB | 70% | |
|
CVE-2010-0822
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Forma… |
— | ExploitDB | 70% | |
|
CVE-2011-3658
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified… |
— | ExploitDB | 70% | |
|
CVE-2009-4484
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as u… |
— | ExploitDB | 70% | — |
|
CVE-2015-0816
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, w… |
— | ExploitDB | 67% | |
|
CVE-2006-4868
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer… |
— | ExploitDB | 61% | |
|
CVE-2013-0757
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before… |
— | ExploitDB | 61% | |
|
CVE-2010-0266
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_ME… |
— | ExploitDB | 55% | |
|
CVE-2010-1663
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass th… |
— | ExploitDB | 54% | |
|
CVE-2002-1143
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the informatio… |
— | ExploitDB | 54% | |
|
CVE-2011-0104
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote atta… |
— | ExploitDB | 53% | |
|
CVE-2001-0538
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary command… |
— | ExploitDB | 53% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.