Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Arsenal public

Exploits

867 CVE indexées ont un exploit public prêt à l'emploi, dont 107 au KEV CISA et 326 touchant une app suivie.

CVE avec exploit
867
Exploits recensés
1 030
Au KEV CISA
107
Sur le parc suivi
326
CVE Sévérité Apps
CVE-2017-5447

An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash a…

CRITICAL
CVE-2017-5404

A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node…

CRITICAL
CVE-2026-58644 KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CRITICAL
CVE-2019-1151

Microsoft Graphics Remote Code Execution Vulnerability

CRITICAL
CVE-2019-1149

Microsoft Graphics Remote Code Execution Vulnerability

CRITICAL
CVE-2019-9792

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailou…

CRITICAL
CVE-2019-1144

Microsoft Graphics Remote Code Execution Vulnerability

CRITICAL
CVE-2019-1145

Microsoft Graphics Remote Code Execution Vulnerability

CRITICAL
CVE-2019-1152

Microsoft Graphics Remote Code Execution Vulnerability

CRITICAL
CVE-2016-7567

Microsoft Security Update Guide entry — NVD enrichira.

CRITICAL
CVE-2019-11703

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain emai…

CRITICAL
CVE-2019-11704

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing cer…

CRITICAL
CVE-2019-11705

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain…

CRITICAL
CVE-2016-3861

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2016-10277

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2017-11120

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2019-2107

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2016-6256

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a…

CRITICAL
CVE-2024-30896

InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized u…

CRITICAL
CVE-2026-58289

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker …

CRITICAL
CVE-2016-2184

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2016-3134

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2016-6828

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2008-0081

Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted…

CRITICAL
CVE-2023-44487 KEV

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams …

HIGH
CVE-2021-41773 KEV

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

HIGH
CVE-2020-0688 KEV

Microsoft Exchange Validation Key Remote Code Execution Vulnerability

HIGH
CVE-2017-11882 KEV

Microsoft Office Memory Corruption Vulnerability

HIGH
CVE-2025-53771

Microsoft SharePoint Server Spoofing Vulnerability

HIGH
CVE-2021-27065 KEV

Microsoft Exchange Server Remote Code Execution Vulnerability

HIGH
CVE-2017-0147 KEV

Windows SMB Information Disclosure Vulnerability

HIGH
CVE-2024-6387

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to…

HIGH
CVE-2011-0611

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR …

HIGH
CVE-2017-0144 KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

HIGH
CVE-2020-0618 KEV

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests…

HIGH
CVE-2024-29059 KEV

.NET Framework Information Disclosure Vulnerability

HIGH
CVE-2019-5736

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2021-33766 KEV

Microsoft Exchange Server Information Disclosure Vulnerability

HIGH
CVE-2018-20250 KEV

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE…

HIGH
CVE-2021-4034 KEV

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed…

HIGH
CVE-2016-0189 KEV

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products,…

HIGH
CVE-2026-43284

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_S…

HIGH
CVE-2026-43500

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags a…

HIGH
CVE-2025-11371 KEV

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusi…

HIGH
CVE-2023-41763 KEV

Skype for Business Elevation of Privilege Vulnerability

HIGH
CVE-2017-8570 KEV

Microsoft Office Remote Code Execution Vulnerability

HIGH
CVE-2017-0145 KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

HIGH
CVE-2022-0847 KEV

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2020-0601 KEV

Windows CryptoAPI Spoofing Vulnerability

HIGH
CVE-2016-2107

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH

Exploits agrégés depuis ExploitDB, Nuclei, Metasploit et les PoC GitHub, mappés aux CVE que Scout indexe. À des fins de recherche défensive et de test d'exposition uniquement.