Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2016-3225
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows … |
HIGH | ExploitDB | 43% | |
|
CVE-2016-3235
KEV Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle libr… |
HIGH | ExploitDB | 43% | — |
|
CVE-2016-0145
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 43% | |
|
CVE-2017-0061
Microsoft Color Management Information Disclosure Vulnerability |
HIGH | ExploitDB | 43% | — |
|
CVE-2017-0121
Windows Uniscribe Information Disclosure Vulnerability |
HIGH | ExploitDB | 42% | |
|
CVE-2019-0841
KEV Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 41% | |
|
CVE-2016-3386
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (me… |
HIGH | ExploitDB | 41% | |
|
CVE-2016-0122
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility … |
HIGH | ExploitDB | 41% | |
|
CVE-2023-29336
KEV Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 41% | |
|
CVE-2016-3371
Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 40% | |
|
CVE-2016-1096
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 40% | |
|
CVE-2016-1102
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 40% | |
|
CVE-2016-1104
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 40% | |
|
CVE-2021-27928
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 b… |
HIGH | ExploitDB | 38% | — |
|
CVE-2016-1101
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-1103
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-1105
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-4108
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 38% | |
|
CVE-2019-11707
KEV A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an e… |
HIGH | ExploitDB | 38% | |
|
CVE-2016-1106
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Interne… |
HIGH | ExploitDB | 37% | |
|
CVE-2025-1097
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingr… |
HIGH | ExploitDB Nuclei | 36% | — |
|
CVE-2017-0063
Microsoft Color Management Information Disclosure Vulnerability |
HIGH | ExploitDB | 35% | |
|
CVE-2025-24514
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annot… |
HIGH | ExploitDB Nuclei | 33% | — |
|
CVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x … |
HIGH | ExploitDB | 31% | |
|
CVE-2025-26633
KEV Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
HIGH | ExploitDB | 30% | |
|
CVE-2016-7182
Graphics Component Font Parsing Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 30% | |
|
CVE-2019-1405
KEV An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM obje… |
HIGH | ExploitDB | 30% | |
|
CVE-2016-0016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold … |
HIGH | ExploitDB | 30% | |
|
CVE-2019-9810
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buf… |
HIGH | ExploitDB | 30% | |
|
CVE-2024-38193
KEV Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 29% | |
|
CVE-2016-3324
Internet Explorer Memory Corruption Vulnerability |
HIGH | ExploitDB | 28% | — |
|
CVE-2025-11001
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe… |
HIGH | ExploitDB | 27% | |
|
CVE-2025-30397
KEV Scripting Engine Memory Corruption Vulnerability |
HIGH | ExploitDB | 27% | |
|
CVE-2018-8269
OData Denial of Service Vulnerability |
HIGH | ExploitDB | 27% | — |
|
CVE-2024-38473
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | Nuclei | 26% | — |
|
CVE-1999-0236
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. |
HIGH | ExploitDB | 26% | — |
|
CVE-2025-50154
Microsoft Windows File Explorer Spoofing Vulnerability |
HIGH | ExploitDB | 26% | |
|
CVE-2024-49138
KEV Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 25% | |
|
CVE-2019-0572
Windows Data Sharing Service Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 25% | |
|
CVE-2017-11906
Internet Explorer Information Disclosure Vulnerability |
HIGH | ExploitDB | 25% | — |
|
CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability |
HIGH | ExploitDB | 25% | |
|
CVE-2019-1117
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 24% | |
|
CVE-2019-1118
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 24% | |
|
CVE-2018-8527
SQL Server Management Studio Information Disclosure Vulnerability |
HIGH | ExploitDB | 23% | — |
|
CVE-2018-8532
SQL Server Management Studio Information Disclosure Vulnerability |
HIGH | ExploitDB | 23% | — |
|
CVE-2017-0118
Windows Uniscribe Information Disclosure Vulnerability |
HIGH | ExploitDB | 23% | |
|
CVE-2024-21320
Windows Themes Spoofing Vulnerability |
HIGH | ExploitDB | 23% | |
|
CVE-2017-8683
Microsoft Graphics Component Information Disclosure Vulnerability |
HIGH | ExploitDB | 23% | |
|
CVE-2017-0085
Windows Uniscribe Information Disclosure Vulnerability |
HIGH | ExploitDB | 22% | — |
|
CVE-2017-0091
Windows Uniscribe Information Disclosure Vulnerability |
HIGH | ExploitDB | 22% | — |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.