Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2021-34473
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2021-40438
KEV A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue … |
CRITICAL | Nuclei | 100% | — |
|
CVE-2021-44228
KEV Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio… |
CRITICAL | ExploitDB Nuclei | 100% | 1 |
|
CVE-2025-53770
KEV Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over… |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2021-26855
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2024-4577
KEV Argument Injection in PHP-CGI |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2023-29357
KEV Microsoft SharePoint Server Elevation of Privilege Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2025-59287
KEV Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2021-38647
KEV Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 100% | — |
|
CVE-2020-0796
KEV A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles ce… |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2025-1974
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod … |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2019-5544
KEV Microsoft Security Update Guide entry — NVD enrichira. |
CRITICAL | Nuclei | 97% | — |
|
CVE-2025-12480
KEV Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup… |
CRITICAL | Nuclei | 91% | — |
|
CVE-2020-11984
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
CRITICAL | Nuclei | 90% | — |
|
CVE-2025-49844
Redis Lua Use-After-Free may lead to remote code execution |
CRITICAL | Nuclei | 87% | — |
|
CVE-2021-28480
Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 71% | — |
|
CVE-2020-16952
Microsoft SharePoint Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 71% | — |
|
CVE-2025-62168
Squid vulnerable to information disclosure via authentication credential leakage in error handling |
CRITICAL | Nuclei | 63% | — |
|
CVE-2025-14611
KEV Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cry… |
CRITICAL | Nuclei | 53% | — |
|
CVE-2026-55040
KEV Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. |
CRITICAL | Nuclei | 40% | — |
|
CVE-2021-28481
Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | Nuclei | 36% | — |
|
CVE-2023-34990
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute una… |
CRITICAL | Nuclei | 25% | — |
|
CVE-2023-34993
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 t… |
CRITICAL | Nuclei | 18% | — |
|
CVE-2026-58644
KEV Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
CRITICAL | Nuclei | 16% | — |
|
CVE-2021-41773
KEV Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
HIGH | ExploitDB Nuclei | 100% | — |
|
CVE-2025-53771
Microsoft SharePoint Server Spoofing Vulnerability |
HIGH | Nuclei | 100% | — |
|
CVE-2020-0618
KEV A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests… |
HIGH | ExploitDB Nuclei | 99% | — |
|
CVE-2024-29059
KEV .NET Framework Information Disclosure Vulnerability |
HIGH | Nuclei | 99% | — |
|
CVE-2021-33766
KEV Microsoft Exchange Server Information Disclosure Vulnerability |
HIGH | Nuclei | 98% | — |
|
CVE-2025-11371
KEV In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusi… |
HIGH | Nuclei | 92% | — |
|
CVE-2023-41763
KEV Skype for Business Elevation of Privilege Vulnerability |
HIGH | Nuclei | 90% | — |
|
CVE-2025-1098
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mir… |
HIGH | ExploitDB Nuclei | 83% | — |
|
CVE-2024-23334
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal |
HIGH | ExploitDB Nuclei | 77% | — |
|
CVE-2021-31195
Microsoft Exchange Server Remote Code Execution Vulnerability |
HIGH | Nuclei | 74% | — |
|
CVE-2024-38472
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious request… |
HIGH | Nuclei | 69% | — |
|
CVE-2019-14322
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. |
HIGH | ExploitDB Nuclei | 56% | — |
|
CVE-2025-1097
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingr… |
HIGH | ExploitDB Nuclei | 36% | — |
|
CVE-2025-24514
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annot… |
HIGH | ExploitDB Nuclei | 33% | — |
|
CVE-2024-38473
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | Nuclei | 26% | — |
|
CVE-2025-46817
Lua library commands may lead to integer overflow and potential RCE |
HIGH | Nuclei | 4% | — |
|
CVE-2026-57219
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint ca… |
HIGH | Nuclei | 2% | — |
|
CVE-2025-49706
KEV Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
MEDIUM | Nuclei | 99% | — |
|
CVE-2021-41349
Microsoft Exchange Server Spoofing Vulnerability |
MEDIUM | Nuclei | 93% | — |
|
CVE-2023-48795
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | Nuclei | 93% | — |
|
CVE-2021-29622
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | Nuclei | 20% | — |
|
CVE-2024-41810
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM | Nuclei | 1% | — |
|
CVE-2025-46819
Redis is vulnerable to DoS via specially crafted LUA scripts |
MEDIUM | Nuclei | 1% | — |
|
CVE-2025-46818
Redis: Authenticated users can execute LUA scripts as a different user |
MEDIUM | Nuclei | 1% | — |
|
CVE-2004-2687
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers t… |
— | ExploitDB Nuclei | 88% | 1 |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.