Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2019-9813
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary mem… |
HIGH | ExploitDB | 7% | |
|
CVE-2018-6064
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker … |
HIGH | ExploitDB | 7% | |
|
CVE-2023-33131
Microsoft Outlook Remote Code Execution Vulnerability |
HIGH | ExploitDB | 6% | |
|
CVE-2018-16083
An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker… |
HIGH | ExploitDB | 5% | |
|
CVE-2015-8664
Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.… |
HIGH | ExploitDB | 5% | |
|
CVE-2018-16071
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruptio… |
HIGH | ExploitDB | 5% | |
|
CVE-2019-5796
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c… |
HIGH | ExploitDB | 5% | |
|
CVE-2019-5797
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption… |
HIGH | ExploitDB | 3% | |
|
CVE-2023-23399
Microsoft Excel Remote Code Execution Vulnerability |
HIGH | ExploitDB | 3% | |
|
CVE-2025-27751
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
HIGH | ExploitDB | 2% | |
|
CVE-2025-47175
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
HIGH | ExploitDB | 2% | |
|
CVE-2025-47165
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
HIGH | ExploitDB | 2% | |
|
CVE-2019-10038
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as … |
HIGH | ExploitDB | 1% | |
|
CVE-2018-6084
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker… |
HIGH | ExploitDB | 1% | |
|
CVE-2009-3459
KEV Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attac… |
HIGH | ExploitDB | — | |
|
CVE-2009-3129
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for… |
HIGH | ExploitDB | — | |
|
CVE-2014-1761
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Ma… |
HIGH | ExploitDB | — | |
|
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap c… |
MEDIUM | ExploitDB | 100% | |
|
CVE-2018-0767
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information t… |
MEDIUM | ExploitDB | 65% | |
|
CVE-2019-5786
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bo… |
MEDIUM | ExploitDB | 62% | |
|
CVE-2018-0780
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain informa… |
MEDIUM | ExploitDB | 59% | |
|
CVE-2019-5825
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap co… |
MEDIUM | ExploitDB | 56% | |
|
CVE-2018-6849
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such … |
MEDIUM | ExploitDB | 29% | |
|
CVE-2016-3388
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remo… |
MEDIUM | ExploitDB | 28% | |
|
CVE-2017-8652
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information… |
MEDIUM | ExploitDB | 23% | |
|
CVE-2017-8644
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information… |
MEDIUM | ExploitDB | 15% | |
|
CVE-2016-0772
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when… |
MEDIUM | ExploitDB | 15% | |
|
CVE-2018-0891
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Win… |
MEDIUM | ExploitDB | 14% | |
|
CVE-2020-6519
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a cra… |
MEDIUM | ExploitDB | 11% | |
|
CVE-2019-0612
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By … |
MEDIUM | ExploitDB | 11% | |
|
CVE-2018-13042
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebit… |
MEDIUM | ExploitDB | 8% | |
|
CVE-2019-9816
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing fo… |
MEDIUM | ExploitDB | 6% | |
|
CVE-2017-5124
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary… |
MEDIUM | ExploitDB | 5% | |
|
CVE-2017-2480
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2… |
MEDIUM | ExploitDB | 4% | |
|
CVE-2018-6130
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially … |
MEDIUM | ExploitDB | 3% | |
|
CVE-2018-6129
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out … |
MEDIUM | ExploitDB | 3% | |
|
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. |
MEDIUM | ExploitDB | 2% | |
|
CVE-2016-3325
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, … |
LOW | ExploitDB | 54% | |
|
CVE-2004-2687
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers t… |
— | ExploitDB Nuclei | 88% | |
|
CVE-2011-2371
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.1… |
— | ExploitDB | 76% | |
|
CVE-2013-0758
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 1… |
— | ExploitDB | 73% | |
|
CVE-2006-0295
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to e… |
— | ExploitDB | 71% | |
|
CVE-2011-3658
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified… |
— | ExploitDB | 70% | |
|
CVE-2015-0816
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, w… |
— | ExploitDB | 67% | |
|
CVE-2013-0757
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before… |
— | ExploitDB | 61% | |
|
CVE-2010-1663
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass th… |
— | ExploitDB | 54% | |
|
CVE-2013-0753
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.… |
— | ExploitDB | 51% | |
|
CVE-2012-3993
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before… |
— | ExploitDB | 43% | |
|
CVE-2013-1710
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8… |
— | ExploitDB | 40% | |
|
CVE-2011-3659
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0,… |
— | ExploitDB | 37% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.