Arsenal public
Exploits
867 CVE indexées ont un exploit public prêt à l'emploi, dont 107 au KEV CISA et 326 touchant une app suivie.
- CVE avec exploit
- 867
- Exploits recensés
- 1 030
- Au KEV CISA
- 107
- Sur le parc suivi
- 326
| CVE | Sévérité | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2017-5447
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash a… |
CRITICAL | ExploitDB | 17% | |
|
CVE-2017-5404
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node… |
CRITICAL | ExploitDB | 17% | |
|
CVE-2026-58644
KEV Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
CRITICAL | Nuclei | 16% | — |
|
CVE-2019-1151
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 15% | |
|
CVE-2019-1149
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 14% | |
|
CVE-2019-9792
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailou… |
CRITICAL | ExploitDB | 13% | |
|
CVE-2019-1144
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 13% | |
|
CVE-2019-1145
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 13% | |
|
CVE-2019-1152
Microsoft Graphics Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 13% | |
|
CVE-2016-7567
Microsoft Security Update Guide entry — NVD enrichira. |
CRITICAL | ExploitDB | 12% | — |
|
CVE-2019-11703
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain emai… |
CRITICAL | ExploitDB | 11% | |
|
CVE-2019-11704
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing cer… |
CRITICAL | ExploitDB | 11% | |
|
CVE-2019-11705
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain… |
CRITICAL | ExploitDB | 10% | |
|
CVE-2016-3861
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 10% | |
|
CVE-2016-10277
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 10% | |
|
CVE-2017-11120
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 9% | |
|
CVE-2019-2107
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 9% | |
|
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a… |
CRITICAL | ExploitDB | 8% | — |
|
CVE-2024-30896
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized u… |
CRITICAL | ExploitDB | 5% | — |
|
CVE-2026-58289
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker … |
CRITICAL | ExploitDB | 2% | — |
|
CVE-2016-2184
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 2% | |
|
CVE-2016-3134
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 1% | |
|
CVE-2016-6828
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 1% | |
|
CVE-2008-0081
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted… |
CRITICAL | ExploitDB | — | |
|
CVE-2023-44487
KEV The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams … |
HIGH | ExploitDB | 100% | |
|
CVE-2021-41773
KEV Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
HIGH | ExploitDB Nuclei | 100% | — |
|
CVE-2020-0688
KEV Microsoft Exchange Validation Key Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-11882
KEV Microsoft Office Memory Corruption Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2025-53771
Microsoft SharePoint Server Spoofing Vulnerability |
HIGH | Nuclei | 100% | — |
|
CVE-2021-27065
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-0147
KEV Windows SMB Information Disclosure Vulnerability |
HIGH | ExploitDB | 100% | |
|
CVE-2024-6387
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to… |
HIGH | ExploitDB | 100% | |
|
CVE-2011-0611
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR … |
HIGH | ExploitDB | 99% | |
|
CVE-2017-0144
KEV The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 99% | |
|
CVE-2020-0618
KEV A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests… |
HIGH | ExploitDB Nuclei | 99% | — |
|
CVE-2024-29059
KEV .NET Framework Information Disclosure Vulnerability |
HIGH | Nuclei | 99% | — |
|
CVE-2019-5736
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 98% | — |
|
CVE-2021-33766
KEV Microsoft Exchange Server Information Disclosure Vulnerability |
HIGH | Nuclei | 98% | — |
|
CVE-2018-20250
KEV In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE… |
HIGH | ExploitDB | 96% | |
|
CVE-2021-4034
KEV A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed… |
HIGH | ExploitDB | 95% | — |
|
CVE-2016-0189
KEV The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products,… |
HIGH | ExploitDB | 94% | — |
|
CVE-2026-43284
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_S… |
HIGH | ExploitDB | 93% | — |
|
CVE-2026-43500
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags a… |
HIGH | ExploitDB | 93% | — |
|
CVE-2025-11371
KEV In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusi… |
HIGH | Nuclei | 92% | — |
|
CVE-2023-41763
KEV Skype for Business Elevation of Privilege Vulnerability |
HIGH | Nuclei | 90% | — |
|
CVE-2017-8570
KEV Microsoft Office Remote Code Execution Vulnerability |
HIGH | ExploitDB | 90% | — |
|
CVE-2017-0145
KEV The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 90% | |
|
CVE-2022-0847
KEV Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 90% | |
|
CVE-2020-0601
KEV Windows CryptoAPI Spoofing Vulnerability |
HIGH | ExploitDB | 89% | |
|
CVE-2016-2107
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 89% |
Exploits agrégés depuis ExploitDB, Nuclei, Metasploit et les PoC GitHub, mappés aux CVE que Scout indexe. À des fins de recherche défensive et de test d'exposition uniquement.