Skip to content
Appaloosa Scout
Language selector
fr en

Public arsenal

Exploits

867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.

CVEs with exploit
867
Exploits catalogued
1,030
In CISA KEV
107
On tracked fleet
326
CVE Severity Apps
CVE-2021-34473 KEV

Microsoft Exchange Server Remote Code Execution Vulnerability

CRITICAL
CVE-2021-40438 KEV

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue …

CRITICAL
CVE-2021-44228 KEV

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio…

CRITICAL 1
CVE-2025-53770 KEV

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over…

CRITICAL
CVE-2021-26855 KEV

Microsoft Exchange Server Remote Code Execution Vulnerability

CRITICAL
CVE-2024-4577 KEV

Argument Injection in PHP-CGI

CRITICAL
CVE-2023-29357 KEV

Microsoft SharePoint Server Elevation of Privilege Vulnerability

CRITICAL
CVE-2025-59287 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CRITICAL
CVE-2021-38647 KEV

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CRITICAL
CVE-2020-0796 KEV

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles ce…

CRITICAL
CVE-2025-1974

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod …

CRITICAL
CVE-2019-5544 KEV

Microsoft Security Update Guide entry — NVD enrichira.

CRITICAL
CVE-2025-12480 KEV

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup…

CRITICAL
CVE-2020-11984

Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

CRITICAL
CVE-2025-49844

Redis Lua Use-After-Free may lead to remote code execution

CRITICAL
CVE-2021-28480

Microsoft Exchange Server Remote Code Execution Vulnerability

CRITICAL
CVE-2020-16952

Microsoft SharePoint Remote Code Execution Vulnerability

CRITICAL
CVE-2025-62168

Squid vulnerable to information disclosure via authentication credential leakage in error handling

CRITICAL
CVE-2025-14611 KEV

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cry…

CRITICAL
CVE-2026-55040 KEV

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

CRITICAL
CVE-2021-28481

Microsoft Exchange Server Remote Code Execution Vulnerability

CRITICAL
CVE-2023-34990

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute una…

CRITICAL
CVE-2023-34993

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 t…

CRITICAL
CVE-2026-58644 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CRITICAL
CVE-2021-41773 KEV

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

HIGH
CVE-2025-53771

Microsoft SharePoint Server Spoofing Vulnerability

HIGH
CVE-2020-0618 KEV

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests…

HIGH
CVE-2024-29059 KEV

.NET Framework Information Disclosure Vulnerability

HIGH
CVE-2021-33766 KEV

Microsoft Exchange Server Information Disclosure Vulnerability

HIGH
CVE-2025-11371 KEV

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusi…

HIGH
CVE-2023-41763 KEV

Skype for Business Elevation of Privilege Vulnerability

HIGH
CVE-2025-1098

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mir…

HIGH
CVE-2024-23334

aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal

HIGH
CVE-2021-31195

Microsoft Exchange Server Remote Code Execution Vulnerability

HIGH
CVE-2024-38472

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious request…

HIGH
CVE-2019-14322

In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

HIGH
CVE-2025-1097

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingr…

HIGH
CVE-2025-24514

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annot…

HIGH
CVE-2024-38473

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2025-46817

Lua library commands may lead to integer overflow and potential RCE

HIGH
CVE-2026-57219

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint ca…

HIGH
CVE-2025-49706 KEV

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

MEDIUM
CVE-2021-41349

Microsoft Exchange Server Spoofing Vulnerability

MEDIUM
CVE-2023-48795

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2021-29622

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2024-41810

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM
CVE-2025-46819

Redis is vulnerable to DoS via specially crafted LUA scripts

MEDIUM
CVE-2025-46818

Redis: Authenticated users can execute LUA scripts as a different user

MEDIUM
CVE-2004-2687

distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers t…

1

Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.