Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.724exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
22.429 exploits
Referência
CVE-2019-9581
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISCO
abrir
Referência
CVE-2026-9426
Edimax EW-7438RPn formHwSet stack-based overflow
41RISCO
abrir
Referência
CVE-2026-9416
code-projects Employee Management System myprofile.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-9415
code-projects Employee Management System eloginwel.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-9413
SourceCodester Indian Invoicing System category.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-9412
SourceCodester Indian Invoicing System Backend Endpoint access control
33RISCO
abrir
ReferênciaVexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
CVE-2019-9601dosandroid
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISCO
abrir
Referência
CVE-2026-9411
SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection
33RISCO
abrir
Referência
CVE-2026-9410
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
33RISCO
abrir
Referência
CVE-2026-9409
Sushmi-pal Invoice-System User Management user improper authorization
33RISCO
abrir
Referência
CVE-2026-9407
Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection
48RISCO
abrir
Referência
CVE-2026-9406
Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection
48RISCO
abrir
Referência
eBrigade ERP 4.5 - Arbitrary File Download
CVE-2019-9622webappsphp
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d
23RISCO
abrir
Referência
CVE-2019-9670
CVE-2019-9670CRITICALsob ataque
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir
Referência
CVE-2019-9670
CVE-2019-9670CRITICALsob ataque
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir
Referência
CVE-2026-67349
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
41RISCO
abrir
Referência
CVE-2026-67348
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
41RISCO
abrir
Referência
CVE-2026-67347
Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
33RISCO
abrir
Referência
CVE-2026-67345
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
41RISCO
abrir
Referência
CVE-2026-14310
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
33RISCO
abrir
Referência
CVE-2026-14305
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
33RISCO
abrir
ReferênciaVexDay Proof
Free MP3 CD Ripper 2.6 - '.mp3' Buffer Overflow (SEH)
CVE-2019-9766localwindows_x86
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Free MP3 CD Ripper 2.6 - '.wma' Local Buffer Overflow (SEH)
CVE-2019-9767localwindows_x86
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
AirMore 1.6.1 - Denial of Service (PoC)
CVE-2019-9831dosandroid
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via
23RISCO
abrir
Referência
AirDrop 2.0 - Denial of Service (DoS)
CVE-2019-9832dosandroid
The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that m
23RISCO
abrir
Referência
NetData 1.13.0 - HTML Injection
CVE-2019-9834webappsmultiple
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an impor
23RISCO
abrir
Referência
CVE-2026-9368
NousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandbox
33RISCO
abrir
Referência
CVE-2026-9365
Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow
33RISCO
abrir
Referência
CVE-2026-9364
projectworlds Online Art Gallery Shop adminHome.php sql injection
33RISCO
abrir
Referência
CVE-2026-9363
Edimax EW-7438RPn POST Request formEZCHNwlanSetu formEZCHNwlanSetup command injection
33RISCO
abrir
anteriorpágina 555 / 748próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.