Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2018-8384
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 62% | — |
|
CVE-2025-32463
KEV Sudo before 1.9.17p1 allows local users to obtain root access |
CRITICAL | ExploitDB | 59% | — |
|
CVE-2017-8618
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 58% | — |
|
CVE-2017-0089
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 57% | — |
|
CVE-2019-11708
KEV Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the n… |
CRITICAL | ExploitDB | 56% | 2 |
|
CVE-2017-11810
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 55% | — |
|
CVE-2025-14611
KEV Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cry… |
CRITICAL | Nuclei | 53% | — |
|
CVE-2016-3288
Internet Explorer Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 52% | — |
|
CVE-2016-3303
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 51% | — |
|
CVE-2016-3304
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 51% | — |
|
CVE-2017-0108
Windows Graphics Component Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 50% | — |
|
CVE-2017-8594
Internet Explorer Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 50% | — |
|
CVE-2017-8538
Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 50% | — |
|
CVE-2017-11890
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 50% | — |
|
CVE-2017-8682
Win32k Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 50% | — |
|
CVE-2017-11793
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 50% | — |
|
CVE-2017-11855
Internet Explorer Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 49% | — |
|
CVE-2017-8541
Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 48% | — |
|
CVE-2018-8544
Windows VBScript Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 48% | — |
|
CVE-2017-11903
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 47% | — |
|
CVE-2017-0202
Internet Explorer Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 46% | — |
|
CVE-2016-3301
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 44% | — |
|
CVE-2017-8558
Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 44% | — |
|
CVE-2010-1205
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow re… |
CRITICAL | ExploitDB | 43% | 7 |
|
CVE-2017-0072
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 43% | — |
|
CVE-2017-0083
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 43% | — |
|
CVE-2017-0086
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 43% | — |
|
CVE-2017-0087
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 43% | — |
|
CVE-2017-0090
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 43% | — |
|
CVE-2016-7274
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 42% | — |
|
CVE-2017-0088
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 42% | — |
|
CVE-2026-55040
KEV Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. |
CRITICAL | Nuclei | 40% | — |
|
CVE-2017-0283
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 39% | — |
|
CVE-2024-0132
NVIDIA: CVE-2024-0132 Container Toolkit 1.16.1 and Earlier Time-of-check Time-of Use Vulnerability |
CRITICAL | ExploitDB | 39% | — |
|
CVE-2017-0084
Windows Uniscribe Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 37% | — |
|
CVE-2021-28481
Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 36% | — |
|
CVE-2017-5375
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulne… |
CRITICAL | ExploitDB | 34% | 2 |
|
CVE-2019-0667
Windows VBScript Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 31% | — |
|
CVE-2017-0561
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 30% | — |
|
CVE-2019-1150
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 29% | — |
|
CVE-2023-34990
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute una… |
CRITICAL | Nuclei | 25% | — |
|
CVE-2014-4650
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separator… |
CRITICAL | ExploitDB | 25% | 3 |
|
CVE-2017-0781
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 23% | — |
|
CVE-2016-9899
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vul… |
CRITICAL | ExploitDB | 21% | 2 |
|
CVE-2018-5159
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resultin… |
CRITICAL | ExploitDB | 21% | 2 |
|
CVE-2019-9791
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compi… |
CRITICAL | ExploitDB | 20% | 2 |
|
CVE-2017-5465
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inac… |
CRITICAL | ExploitDB | 19% | 2 |
|
CVE-2023-34993
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 t… |
CRITICAL | Nuclei | 18% | — |
|
CVE-2017-0160
.NET Framework Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 18% | — |
|
CVE-2025-24085
KEV A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.… |
CRITICAL | ExploitDB | 18% | — |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.