Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2010-0315
WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, fo… |
— | ExploitDB | 7% | |
|
CVE-2008-6996
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attac… |
— | ExploitDB | 6% | |
|
CVE-2005-4809
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in… |
— | ExploitDB | 6% | |
|
CVE-2007-3845
Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attac… |
— | ExploitDB | 6% | |
|
CVE-2006-3912
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact. |
— | ExploitDB | 6% | |
|
CVE-2010-3906
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or … |
— | ExploitDB | 6% | |
|
CVE-2007-4725
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 bet… |
— | ExploitDB | 6% | |
|
CVE-2014-1564
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for… |
— | ExploitDB | 5% | |
|
CVE-2007-3844
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-si… |
— | ExploitDB | 5% | |
|
CVE-2013-6627
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status… |
— | ExploitDB | 5% | |
|
CVE-2004-0648
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary progr… |
— | ExploitDB | 5% | |
|
CVE-2006-1045
The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not… |
— | ExploitDB | 5% | |
|
CVE-2008-6995
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of se… |
— | ExploitDB | 5% | |
|
CVE-2008-7061
The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0… |
— | ExploitDB | 4% | |
|
CVE-2008-4340
Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML doc… |
— | ExploitDB | 4% | |
|
CVE-2008-5749
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary comma… |
— | ExploitDB | 4% | |
|
CVE-2011-2841
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allo… |
— | ExploitDB | 4% | |
|
CVE-2008-6997
Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a… |
— | ExploitDB | 4% | |
|
CVE-2012-4908
Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local … |
— | ExploitDB | 3% | |
|
CVE-2012-4906
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to ob… |
— | ExploitDB | 3% | |
|
CVE-2009-1514
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) vi… |
— | ExploitDB | 3% | |
|
CVE-2006-0836
Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into import… |
— | ExploitDB | 3% | |
|
CVE-2009-0374
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves … |
— | ExploitDB | 2% | |
|
CVE-2008-7246
Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the windo… |
— | ExploitDB | 2% | |
|
CVE-2012-5851
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all poss… |
— | ExploitDB | 2% | |
|
CVE-2012-4909
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application. |
— | ExploitDB | 2% | |
|
CVE-2009-2352
Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote at… |
— | ExploitDB | 2% | |
|
CVE-2013-6166
Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions… |
— | ExploitDB | 2% | |
|
CVE-2012-4905
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitr… |
— | ExploitDB | 2% | |
|
CVE-2005-4620
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: … |
— | ExploitDB | 1% | |
|
CVE-2006-1542
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local … |
— | ExploitDB | 1% | |
|
CVE-2012-2764
Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges vi… |
— | ExploitDB | 0% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.