Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2019-0573
Windows Data Sharing Service Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 20% | |
|
CVE-2016-3387
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remo… |
HIGH | ExploitDB | 20% | |
|
CVE-2019-1119
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 19% | |
|
CVE-2019-0574
Windows Data Sharing Service Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 19% | |
|
CVE-2019-1215
KEV Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 19% | |
|
CVE-2019-1322
KEV Microsoft Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 19% | |
|
CVE-2019-12735
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 19% | — |
|
CVE-2020-6507
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruptio… |
HIGH | ExploitDB | 19% | |
|
CVE-2018-8897
Windows Kernel Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 19% | |
|
CVE-2019-0566
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Priv… |
HIGH | ExploitDB | 19% | |
|
CVE-2019-1124
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 18% | |
|
CVE-2017-0062
Windows GDI Information Disclosure Vulnerability |
HIGH | ExploitDB | 18% | |
|
CVE-2016-3373
Windows Kernel Local Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 17% | |
|
CVE-2019-6706
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is … |
HIGH | ExploitDB | 17% | — |
|
CVE-2016-3237
Kerberos Security Feature Bypass Vulnerability |
HIGH | ExploitDB | 17% | |
|
CVE-2019-1120
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 17% | |
|
CVE-2019-1121
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 17% | |
|
CVE-2019-1122
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 17% | |
|
CVE-2019-1123
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 17% | |
|
CVE-2019-1128
DirectWrite Remote Code Execution Vulnerability |
HIGH | ExploitDB | 17% | |
|
CVE-2017-8535
Microsoft Malware Protection Engine Denial of Service Vulnerability |
HIGH | ExploitDB | 17% | — |
|
CVE-2017-8536
Microsoft Malware Protection Engine Denial of Service Vulnerability |
HIGH | ExploitDB | 17% | — |
|
CVE-2017-8537
Microsoft Malware Protection Engine Denial of Service Vulnerability |
HIGH | ExploitDB | 17% | — |
|
CVE-2017-0060
Windows GDI Information Disclosure Vulnerability |
HIGH | ExploitDB | 16% | |
|
CVE-2019-0571
Windows Data Sharing Service Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 16% | |
|
CVE-2025-47166
Microsoft SharePoint Server Remote Code Execution Vulnerability |
HIGH | ExploitDB | 16% | — |
|
CVE-2018-8463
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer san… |
HIGH | ExploitDB | 15% | |
|
CVE-2018-8469
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer san… |
HIGH | ExploitDB | 15% | |
|
CVE-2019-1019
Microsoft Windows Security Feature Bypass Vulnerability |
HIGH | ExploitDB | 15% | |
|
CVE-2018-0744
Windows Kernel Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 15% | |
|
CVE-2019-1347
Windows Denial of Service Vulnerability |
HIGH | ExploitDB | 15% | |
|
CVE-2025-27210
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 15% | — |
|
CVE-2017-0211
Windows OLE Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 14% | |
|
CVE-2016-0165
KEV The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Se… |
HIGH | ExploitDB | 14% | |
|
CVE-2017-10661
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 13% | |
|
CVE-2019-1245
DirectWrite Information Disclosure Vulnerability |
HIGH | ExploitDB | 13% | |
|
CVE-2016-3376
Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 13% | |
|
CVE-2019-1244
DirectWrite Information Disclosure Vulnerability |
HIGH | ExploitDB | 12% | |
|
CVE-2018-8468
Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 12% | |
|
CVE-2019-1253
KEV Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 12% | |
|
CVE-2016-0070
Windows Kernel Local Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 11% | |
|
CVE-2016-9651
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote at… |
HIGH | ExploitDB | 11% | |
|
CVE-2016-8655
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 11% | |
|
CVE-2019-1343
Windows Denial of Service Vulnerability |
HIGH | ExploitDB | 11% | |
|
CVE-2019-1346
Windows Denial of Service Vulnerability |
HIGH | ExploitDB | 11% | |
|
CVE-2017-0263
KEV Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 10% | |
|
CVE-2025-21333
KEV Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 10% | |
|
CVE-2019-1132
KEV Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 10% | — |
|
CVE-2019-11706
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing c… |
HIGH | ExploitDB | 10% | |
|
CVE-2017-0259
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 10% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.