Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 108 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 108
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2019-0571
Windows Data Sharing Service Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 16% | |
|
CVE-2025-47166
Microsoft SharePoint Server Remote Code Execution Vulnerability |
HIGH | ExploitDB | 16% | — |
|
CVE-2018-8463
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer san… |
HIGH | ExploitDB | 15% | |
|
CVE-2018-8469
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer san… |
HIGH | ExploitDB | 15% | |
|
CVE-2019-1019
Microsoft Windows Security Feature Bypass Vulnerability |
HIGH | ExploitDB | 15% | |
|
CVE-2018-0744
Windows Kernel Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 15% | |
|
CVE-2019-1347
Windows Denial of Service Vulnerability |
HIGH | ExploitDB | 15% | |
|
CVE-2025-27210
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 15% | — |
|
CVE-2017-0211
Windows OLE Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 14% | |
|
CVE-2016-0165
KEV The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Se… |
HIGH | ExploitDB | 14% | |
|
CVE-2017-10661
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 13% | |
|
CVE-2019-1245
DirectWrite Information Disclosure Vulnerability |
HIGH | ExploitDB | 13% | |
|
CVE-2016-3376
Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 13% | |
|
CVE-2019-1244
DirectWrite Information Disclosure Vulnerability |
HIGH | ExploitDB | 12% | |
|
CVE-2018-8468
Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 12% | |
|
CVE-2019-1253
KEV Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 12% | |
|
CVE-2016-0070
Windows Kernel Local Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 11% | |
|
CVE-2016-9651
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote at… |
HIGH | ExploitDB | 11% | |
|
CVE-2016-8655
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 11% | |
|
CVE-2019-1343
Windows Denial of Service Vulnerability |
HIGH | ExploitDB | 11% | |
|
CVE-2019-1346
Windows Denial of Service Vulnerability |
HIGH | ExploitDB | 11% | |
|
CVE-2017-0263
KEV Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 10% | |
|
CVE-2025-21333
KEV Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 10% | |
|
CVE-2019-1132
KEV Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 10% | — |
|
CVE-2019-11706
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing c… |
HIGH | ExploitDB | 10% | |
|
CVE-2017-0259
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 10% | |
|
CVE-2026-46300
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing … |
HIGH | ExploitDB | 9% | — |
|
CVE-2019-5789
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote … |
HIGH | ExploitDB | 9% | |
|
CVE-2018-6092
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute… |
HIGH | ExploitDB | 9% | |
|
CVE-2025-2783
KEV Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remo… |
HIGH | ExploitDB | 9% | |
|
CVE-2019-5788
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a rem… |
HIGH | ExploitDB | 9% | |
|
CVE-2018-1038
Windows Kernel Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 9% | — |
|
CVE-2023-33145
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
HIGH | ExploitDB | 9% | — |
|
CVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusi… |
HIGH | ExploitDB | 8% | — |
|
CVE-2017-13262
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 8% | |
|
CVE-2017-0245
Win32k Information Disclosure Vulnerability |
HIGH | ExploitDB | 8% | — |
|
CVE-2017-0569
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 8% | |
|
CVE-2020-0683
KEV Windows Installer Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 8% | |
|
CVE-2018-6126
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory wri… |
HIGH | ExploitDB | 8% | |
|
CVE-2017-0220
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 7% | — |
|
CVE-2017-13260
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 7% | |
|
CVE-2019-9813
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary mem… |
HIGH | ExploitDB | 7% | |
|
CVE-2017-0258
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 7% | |
|
CVE-2017-13261
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 7% | |
|
CVE-2017-13258
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 7% | |
|
CVE-2017-0175
Windows Kernel Information Disclosure Vulnerability |
HIGH | ExploitDB | 7% | — |
|
CVE-2016-3220
atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1… |
HIGH | ExploitDB | 7% | |
|
CVE-2018-6064
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker … |
HIGH | ExploitDB | 7% | |
|
CVE-2016-0075
Windows Kernel Local Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 7% | |
|
CVE-2017-0045
Windows DVD Maker XML External Entity Information Disclosure Vulnerability |
HIGH | ExploitDB | 7% | — |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.