Arsenal public
Exploits
868 CVE indexées ont un exploit public prêt à l'emploi, dont 108 au KEV CISA et 326 touchant une app suivie.
- CVE avec exploit
- 868
- Exploits recensés
- 1 031
- Au KEV CISA
- 108
- Sur le parc suivi
- 326
| CVE | Sévérité | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2017-8570
KEV
Microsoft Office Remote Code Execution Vulnerability |
HIGH | ExploitDB | 90% | — |
|
CVE-2017-0145
KEV
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 90% | |
|
CVE-2022-0847
KEV
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 90% | |
|
CVE-2020-0601
KEV
Windows CryptoAPI Spoofing Vulnerability |
HIGH | ExploitDB | 89% | |
|
CVE-2017-8759
KEV
.NET Framework Remote Code Execution Vulnerability |
HIGH | ExploitDB | 89% | — |
|
CVE-2018-8174
KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript… |
HIGH | ExploitDB | 88% | |
|
CVE-2016-9079
KEV
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i… |
HIGH | ExploitDB | 87% | |
|
CVE-2009-3459
KEV
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attac… |
HIGH | ExploitDB | 87% | |
|
CVE-2017-0213
KEV
Windows COM Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 84% | |
|
CVE-2016-7200
KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 83% | |
|
CVE-2025-33073
KEV
Windows SMB Client Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 83% | |
|
CVE-2019-0752
KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer,… |
HIGH | ExploitDB | 82% | — |
|
CVE-2023-4911
KEV
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 81% | — |
|
CVE-2016-7255
KEV
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S… |
HIGH | ExploitDB | 81% | |
|
CVE-2017-0037
KEV
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::Handle… |
HIGH | ExploitDB | 80% | |
|
CVE-2016-7201
KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 80% | |
|
CVE-2019-1458
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, a… |
HIGH | ExploitDB | 74% | |
|
CVE-2018-8120
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, a… |
HIGH | ExploitDB | 73% | — |
|
CVE-2018-0824
KEV
Microsoft COM for Windows Remote Code Execution Vulnerability |
HIGH | ExploitDB | 73% | |
|
CVE-2019-2215
KEV
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 72% | |
|
CVE-2018-8453
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, a… |
HIGH | ExploitDB | 70% | |
|
CVE-2016-0185
KEV
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via… |
HIGH | ExploitDB | 70% | — |
|
CVE-2013-1690
KEV
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do… |
HIGH | ExploitDB | 69% | |
|
CVE-2019-18426
KEV
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 all… |
HIGH | ExploitDB | 68% | |
|
CVE-2016-0151
KEV
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windo… |
HIGH | ExploitDB | 63% | |
|
CVE-2017-0059
KEV
Microsoft Browser Information Disclosure Vulnerability |
HIGH | ExploitDB | 62% | — |
|
CVE-2024-21338
KEV
Windows Kernel Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 60% | |
|
CVE-2025-24054
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
HIGH | ExploitDB | 59% | |
|
CVE-2017-0101
KEV
Windows Transaction Manager Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 57% | — |
|
CVE-2019-0541
KEV
MSHTML Engine Remote Code Execution Vulnerability |
HIGH | ExploitDB | 53% | — |
|
CVE-2019-0808
KEV
Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 53% | — |
|
CVE-2019-17026
KEV
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of … |
HIGH | ExploitDB | 46% | |
|
CVE-2019-0803
KEV
Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 45% | |
|
CVE-2016-3235
KEV
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle libr… |
HIGH | ExploitDB | 43% | — |
|
CVE-2019-0841
KEV
Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 41% | |
|
CVE-2023-29336
KEV
Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 41% | |
|
CVE-2019-11707
KEV
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an e… |
HIGH | ExploitDB | 38% | |
|
CVE-2025-26633
KEV
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
HIGH | ExploitDB | 30% | |
|
CVE-2019-1405
KEV
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM obje… |
HIGH | ExploitDB | 30% | |
|
CVE-2024-38193
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 29% | |
|
CVE-2025-30397
KEV
Scripting Engine Memory Corruption Vulnerability |
HIGH | ExploitDB | 27% | |
|
CVE-2024-49138
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 26% | |
|
CVE-2021-3560
KEV
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests elevating the privileges of the… |
HIGH | ExploitDB | 24% | — |
|
CVE-2026-2441
KEV
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbo… |
HIGH | ExploitDB | 22% | |
|
CVE-2016-3309
KEV
Windows Kernel Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 20% | |
|
CVE-2019-1215
KEV
Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 19% | |
|
CVE-2019-1322
KEV
Microsoft Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 19% | |
|
CVE-2016-0165
KEV
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Se… |
HIGH | ExploitDB | 14% | |
|
CVE-2019-1253
KEV
Windows Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 12% | |
|
CVE-2017-0263
KEV
Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 10% |
Exploits agrégés depuis ExploitDB, Nuclei, Metasploit et les PoC GitHub, mappés aux CVE que Scout indexe. À des fins de recherche défensive et de test d'exposition uniquement.