Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Arsenal public

Exploits

868 CVE indexées ont un exploit public prêt à l'emploi, dont 108 au KEV CISA et 326 touchant une app suivie.

CVE avec exploit
868
Exploits recensés
1 031
Au KEV CISA
108
Sur le parc suivi
326
CVE Sévérité Apps
CVE-2016-6256

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a…

CRITICAL
CVE-2024-30896

InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized u…

CRITICAL
CVE-2026-58289

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker …

CRITICAL
CVE-2016-2184

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2016-6828

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2016-3134

Indexed via Android Security Bulletin — full NVD metadata pending.

CRITICAL
CVE-2023-44487 KEV

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams …

HIGH
CVE-2021-41773 KEV

Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

HIGH
CVE-2020-0688 KEV

Microsoft Exchange Validation Key Remote Code Execution Vulnerability

HIGH
CVE-2017-11882 KEV

Microsoft Office Memory Corruption Vulnerability

HIGH
CVE-2021-27065 KEV

Microsoft Exchange Server Remote Code Execution Vulnerability

HIGH
CVE-2017-0147 KEV

Windows SMB Information Disclosure Vulnerability

HIGH
CVE-2024-6387

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to…

HIGH
CVE-2011-0611

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR …

HIGH
CVE-2017-0144 KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

HIGH
CVE-2020-0618 KEV

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests…

HIGH
CVE-2019-5736

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2018-20250 KEV

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE…

HIGH
CVE-2021-4034 KEV

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed…

HIGH
CVE-2016-0189 KEV

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products,…

HIGH
CVE-2026-43284

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_S…

HIGH
CVE-2026-43500

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags a…

HIGH
CVE-2017-8570 KEV

Microsoft Office Remote Code Execution Vulnerability

HIGH
CVE-2017-0145 KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2…

HIGH
CVE-2022-0847 KEV

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2020-0601 KEV

Windows CryptoAPI Spoofing Vulnerability

HIGH
CVE-2016-2107

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2017-8759 KEV

.NET Framework Remote Code Execution Vulnerability

HIGH
CVE-2018-8174 KEV

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript…

HIGH
CVE-2016-9079 KEV

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i…

HIGH
CVE-2009-3459 KEV

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attac…

HIGH
CVE-2009-3129

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for…

HIGH
CVE-2017-14491

Indexed via Android Security Bulletin — full NVD metadata pending.

HIGH
CVE-2018-17463

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code…

HIGH
CVE-2017-0213 KEV

Windows COM Elevation of Privilege Vulnerability

HIGH
CVE-2025-1098

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mir…

HIGH
CVE-2016-7200 KEV

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s…

HIGH
CVE-2025-33073 KEV

Windows SMB Client Elevation of Privilege Vulnerability

HIGH
CVE-2019-0752 KEV

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer,…

HIGH
CVE-2023-4911 KEV

Microsoft Security Update Guide entry — NVD enrichira.

HIGH
CVE-2016-7255 KEV

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S…

HIGH
CVE-2017-0037 KEV

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::Handle…

HIGH
CVE-2016-7201 KEV

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s…

HIGH
CVE-2020-6418

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via…

HIGH
CVE-2018-0886

CredSSP Remote Code Execution Vulnerability

HIGH
CVE-2014-1761

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Ma…

HIGH
CVE-2024-23334

aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal

HIGH
CVE-2017-1000117

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result …

HIGH
CVE-2019-0567

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E…

HIGH
CVE-2019-0539

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E…

HIGH

Exploits agrégés depuis ExploitDB, Nuclei, Metasploit et les PoC GitHub, mappés aux CVE que Scout indexe. À des fins de recherche défensive et de test d'exposition uniquement.