Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2017-11839
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacke… |
HIGH | ExploitDB | 62% | |
|
CVE-2018-6065
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prio… |
HIGH | ExploitDB | 60% | |
|
CVE-2017-11840
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 al… |
HIGH | ExploitDB | 60% | |
|
CVE-2017-11841
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 al… |
HIGH | ExploitDB | 60% | |
|
CVE-2017-11870
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user… |
HIGH | ExploitDB | 60% | |
|
CVE-2016-7194
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (me… |
HIGH | ExploitDB | 58% | |
|
CVE-2016-3222
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted w… |
HIGH | ExploitDB | 57% | |
|
CVE-2017-8635
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 an… |
HIGH | ExploitDB | 56% | |
|
CVE-2018-0834
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code ex… |
HIGH | ExploitDB | 55% | |
|
CVE-2017-8657
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in … |
HIGH | ExploitDB | 55% | |
|
CVE-2018-0840
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and… |
HIGH | ExploitDB | 53% | |
|
CVE-2017-8734
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary co… |
HIGH | ExploitDB | 53% | |
|
CVE-2017-8731
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context o… |
HIGH | ExploitDB | 52% | |
|
CVE-2017-8496
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the curr… |
HIGH | ExploitDB | 51% | |
|
CVE-2018-0946
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, ak… |
HIGH | ExploitDB | 51% | |
|
CVE-2018-8133
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 51% | |
|
CVE-2017-8751
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to … |
HIGH | ExploitDB | 50% | |
|
CVE-2016-7189
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scr… |
HIGH | ExploitDB | 48% | |
|
CVE-2016-3316
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file,… |
HIGH | ExploitDB | 47% | |
|
CVE-2019-17026
KEV Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of … |
HIGH | ExploitDB | 47% | |
|
CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, a… |
HIGH | ExploitDB | 45% | |
|
CVE-2016-0111
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of… |
HIGH | ExploitDB | 44% | |
|
CVE-2016-0145
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 43% | |
|
CVE-2016-3386
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (me… |
HIGH | ExploitDB | 41% | |
|
CVE-2016-0122
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility … |
HIGH | ExploitDB | 41% | |
|
CVE-2016-1096
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 40% | |
|
CVE-2016-1102
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 40% | |
|
CVE-2016-1104
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 40% | |
|
CVE-2016-1101
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-1103
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-1105
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-4108
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2019-11707
KEV A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an e… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-1106
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 37% | |
|
CVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x … |
HIGH | ExploitDB | 31% | |
|
CVE-2019-9810
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buf… |
HIGH | ExploitDB | 30% | |
|
CVE-2025-11001
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe… |
HIGH | ExploitDB | 27% | |
|
CVE-2026-2441
KEV Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbo… |
HIGH | ExploitDB | 22% | |
|
CVE-2016-3387
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remo… |
HIGH | ExploitDB | 20% | |
|
CVE-2020-6507
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruptio… |
HIGH | ExploitDB | 19% | |
|
CVE-2019-0566
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Priv… |
HIGH | ExploitDB | 19% | |
|
CVE-2018-8463
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer san… |
HIGH | ExploitDB | 15% | |
|
CVE-2018-8469
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer san… |
HIGH | ExploitDB | 15% | |
|
CVE-2016-9651
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote at… |
HIGH | ExploitDB | 11% | |
|
CVE-2019-11706
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing c… |
HIGH | ExploitDB | 10% | |
|
CVE-2019-5789
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote … |
HIGH | ExploitDB | 9% | |
|
CVE-2018-6092
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute… |
HIGH | ExploitDB | 9% | |
|
CVE-2025-2783
KEV Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remo… |
HIGH | ExploitDB | 9% | |
|
CVE-2019-5788
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a rem… |
HIGH | ExploitDB | 9% | |
|
CVE-2018-6126
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory wri… |
HIGH | ExploitDB | 8% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.