Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2016-6772
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 3% | |
|
CVE-2018-6129
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out … |
MEDIUM | ExploitDB | 3% | |
|
CVE-2016-6689
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 2% | |
|
CVE-2016-4486
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 2% | |
|
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. |
MEDIUM | ExploitDB | 2% | |
|
CVE-2023-1998
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | ExploitDB | 1% | — |
|
CVE-2026-58058
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/… |
MEDIUM | ExploitDB | 1% | — |
|
CVE-2016-4578
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 1% | |
|
CVE-2024-41810
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | Nuclei | 1% | — |
|
CVE-2014-1739
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 1% | |
|
CVE-2025-46819
Redis is vulnerable to DoS via specially crafted LUA scripts |
MEDIUM | Nuclei | 1% | — |
|
CVE-2025-46818
Redis: Authenticated users can execute LUA scripts as a different user |
MEDIUM | Nuclei | 1% | — |
|
CVE-2017-13236
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 1% | |
|
CVE-2023-24626
socket.c in GNU Screen through 4.9.0 when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD) al… |
MEDIUM | ExploitDB | 1% | — |
|
CVE-2018-9488
Indexed via Android Security Bulletin — full NVD metadata pending. |
MEDIUM | ExploitDB | 0% | |
|
CVE-2016-3325
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, … |
LOW | ExploitDB | 54% | |
|
CVE-2019-15126
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (r… |
LOW | ExploitDB | 7% | — |
|
CVE-2025-32462
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed… |
LOW | ExploitDB | 4% | |
|
CVE-2004-2687
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers t… |
— | ExploitDB Nuclei | 88% | |
|
CVE-2011-2371
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.1… |
— | ExploitDB | 76% | |
|
CVE-2013-0758
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 1… |
— | ExploitDB | 73% | |
|
CVE-2004-0204
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 1… |
— | ExploitDB | 72% | |
|
CVE-2006-0295
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to e… |
— | ExploitDB | 71% | |
|
CVE-2011-0105
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value … |
— | ExploitDB | 70% | |
|
CVE-2010-0822
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Forma… |
— | ExploitDB | 70% | |
|
CVE-2011-3658
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified… |
— | ExploitDB | 70% | |
|
CVE-2009-4484
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as u… |
— | ExploitDB | 70% | — |
|
CVE-2015-0816
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, w… |
— | ExploitDB | 67% | |
|
CVE-2006-4868
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer… |
— | ExploitDB | 61% | |
|
CVE-2013-0757
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before… |
— | ExploitDB | 61% | |
|
CVE-2010-0266
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_ME… |
— | ExploitDB | 55% | |
|
CVE-2010-1663
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass th… |
— | ExploitDB | 54% | |
|
CVE-2002-1143
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the informatio… |
— | ExploitDB | 54% | |
|
CVE-2011-0104
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote atta… |
— | ExploitDB | 53% | |
|
CVE-2001-0538
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary command… |
— | ExploitDB | 53% | |
|
CVE-2013-0753
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.… |
— | ExploitDB | 51% | |
|
CVE-2010-0033
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a craft… |
— | ExploitDB | 51% | |
|
CVE-2008-0111
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allo… |
— | ExploitDB | 51% | |
|
CVE-2004-0200
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, al… |
— | ExploitDB | 49% | |
|
CVE-2008-0116
Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted… |
— | ExploitDB | 48% | |
|
CVE-2004-0121
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using the… |
— | ExploitDB | 48% | |
|
CVE-2007-2365
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote… |
— | ExploitDB | 46% | — |
|
CVE-2012-3993
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before… |
— | ExploitDB | 43% | |
|
CVE-2011-0978
Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Offic… |
— | ExploitDB | 43% | |
|
CVE-2007-0031
Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted re… |
— | ExploitDB | 42% | |
|
CVE-2006-3059
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code vi… |
— | ExploitDB | 41% | |
|
CVE-2015-0097
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote… |
— | ExploitDB | 41% | |
|
CVE-2006-6561
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arb… |
— | ExploitDB | 40% | |
|
CVE-2013-1710
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8… |
— | ExploitDB | 40% | |
|
CVE-2010-1900
Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter fo… |
— | ExploitDB | 40% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.