Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2017-8759
KEV .NET Framework Remote Code Execution Vulnerability |
HIGH | ExploitDB | 89% | — |
|
CVE-2018-8174
KEV A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript… |
HIGH | ExploitDB | 89% | |
|
CVE-2016-9079
KEV A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i… |
HIGH | ExploitDB | 87% | |
|
CVE-2017-14491
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 85% | |
|
CVE-2018-17463
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code… |
HIGH | ExploitDB | 85% | |
|
CVE-2017-0213
KEV Windows COM Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 84% | |
|
CVE-2025-1098
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mir… |
HIGH | ExploitDB Nuclei | 83% | — |
|
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 83% | |
|
CVE-2016-7200
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 82% | |
|
CVE-2017-0038
Windows GDI Information Disclosure Vulnerability |
HIGH | ExploitDB | 82% | |
|
CVE-2018-0886
CredSSP Remote Code Execution Vulnerability |
HIGH | ExploitDB | 82% | |
|
CVE-2019-0752
KEV A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer,… |
HIGH | ExploitDB | 82% | — |
|
CVE-2023-4911
KEV Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 81% | — |
|
CVE-2016-7255
KEV Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 81% | |
|
CVE-2018-0758
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 81% | |
|
CVE-2025-33073
KEV Windows SMB Client Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 80% | |
|
CVE-2017-0037
KEV Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::Handle… |
HIGH | ExploitDB | 80% | |
|
CVE-2019-0567
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 80% | |
|
CVE-2016-7201
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 80% | |
|
CVE-2018-0769
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 79% | |
|
CVE-2020-6418
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via… |
HIGH | ExploitDB | 79% | |
|
CVE-2017-0070
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memo… |
HIGH | ExploitDB | 79% | |
|
CVE-2018-0770
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 78% | |
|
CVE-2018-0776
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 78% | |
|
CVE-2018-0777
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 78% | |
|
CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result … |
HIGH | ExploitDB | 78% | |
|
CVE-2024-23334
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal |
HIGH | ExploitDB Nuclei | 77% | — |
|
CVE-2025-6965
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of colu… |
HIGH | ExploitDB | 76% | |
|
CVE-2019-1458
KEV An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, a… |
HIGH | ExploitDB | 74% | |
|
CVE-2017-5715
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 74% | |
|
CVE-2018-8120
KEV An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, a… |
HIGH | ExploitDB | 74% | — |
|
CVE-2021-31195
Microsoft Exchange Server Remote Code Execution Vulnerability |
HIGH | Nuclei | 74% | — |
|
CVE-2016-7202
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary … |
HIGH | ExploitDB | 73% | |
|
CVE-2018-0824
KEV Microsoft COM for Windows Remote Code Execution Vulnerability |
HIGH | ExploitDB | 73% | |
|
CVE-2019-13720
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruptio… |
HIGH | ExploitDB | 73% | |
|
CVE-2017-8729
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due … |
HIGH | ExploitDB | 72% | |
|
CVE-2017-8740
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due … |
HIGH | ExploitDB | 72% | |
|
CVE-2017-8636
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 an… |
HIGH | ExploitDB | 72% | |
|
CVE-2019-2215
KEV Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 72% | |
|
CVE-2017-8641
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 an… |
HIGH | ExploitDB | 72% | |
|
CVE-2016-7241
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (… |
HIGH | ExploitDB | 71% | |
|
CVE-2016-3247
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (… |
HIGH | ExploitDB | 71% | |
|
CVE-2017-8755
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in … |
HIGH | ExploitDB | 71% | |
|
CVE-2018-8279
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memor… |
HIGH | ExploitDB | 71% | |
|
CVE-2018-8229
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 71% | |
|
CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. T… |
HIGH | ExploitDB | 71% | |
|
CVE-2016-7288
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory cor… |
HIGH | ExploitDB | 70% | |
|
CVE-2017-8634
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user due t… |
HIGH | ExploitDB | 70% | |
|
CVE-2019-1184
Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 70% | |
|
CVE-2018-8453
KEV An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, a… |
HIGH | ExploitDB | 70% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.