Skip to content
Appaloosa Scout
Language selector
fr en

Public arsenal

Exploits

867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.

CVEs with exploit
867
Exploits catalogued
1,030
In CISA KEV
107
On tracked fleet
326
CVE Severity Apps
CVE-2019-0808 KEV

Win32k Elevation of Privilege Vulnerability

HIGH
CVE-2017-8734

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary co…

HIGH
CVE-2017-8731

Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context o…

HIGH
CVE-2017-8496

Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the curr…

HIGH
CVE-2018-0946

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, ak…

HIGH
CVE-2016-0199

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory c…

HIGH
CVE-2018-8552

Scripting Engine Memory Corruption Vulnerability

HIGH
CVE-2018-8133

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E…

HIGH
CVE-2017-8751

Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to …

HIGH
CVE-2016-3313

Microsoft Office Memory Corruption Vulnerability

HIGH
CVE-2026-23918

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server…

HIGH
CVE-2016-0015

DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Ser…

HIGH
CVE-2016-0170

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

HIGH
CVE-2019-0768

Internet Explorer Security Feature Bypass Vulnerability

HIGH
CVE-2016-7189

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scr…

HIGH
CVE-2016-3316

Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file,…

HIGH
CVE-2019-17026 KEV

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of …

HIGH
CVE-2018-8413

Windows Theme API Remote Code Execution Vulnerability

HIGH
CVE-2017-11885

Windows RRAS Service Remote Code Execution Vulnerability

HIGH
CVE-2019-0803 KEV

Win32k Elevation of Privilege Vulnerability

HIGH
CVE-2018-8619

Internet Explorer Remote Code Execution Vulnerability

HIGH
CVE-2019-11932

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, a…

HIGH
CVE-2018-8625

Windows VBScript Engine Remote Code Execution Vulnerability

HIGH
CVE-2016-0111

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of…

HIGH
CVE-2018-0866

Scripting Engine Memory Corruption Vulnerability

HIGH
CVE-2016-3225

The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows …

HIGH
CVE-2016-3235 KEV

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle libr…

HIGH
CVE-2016-0145

The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

HIGH
CVE-2017-0061

Microsoft Color Management Information Disclosure Vulnerability

HIGH
CVE-2017-0121

Windows Uniscribe Information Disclosure Vulnerability

HIGH
CVE-2019-0841 KEV

Windows Elevation of Privilege Vulnerability

HIGH
CVE-2016-3386

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (me…

HIGH
CVE-2016-0122

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility …

HIGH
CVE-2023-29336 KEV

Win32k Elevation of Privilege Vulnerability

HIGH
CVE-2016-3371

Windows Elevation of Privilege Vulnerability

HIGH
CVE-2016-1096

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2016-1102

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2016-1104

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2021-27928

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 b…

HIGH
CVE-2016-1101

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2016-1103

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2016-1105

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2016-4108

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2019-11707 KEV

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an e…

HIGH
CVE-2016-1106

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne…

HIGH
CVE-2025-1097

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingr…

HIGH
CVE-2017-0063

Microsoft Color Management Information Disclosure Vulnerability

HIGH
CVE-2025-24514

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annot…

HIGH
CVE-2016-1960

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x …

HIGH
CVE-2025-26633 KEV

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

HIGH

Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.