Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
22.407 exploits
Referência
CVE-2026-56115
Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass
41RISCO
abrir
Referência
CVE-2026-56109
ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c
41RISCO
abrir
Referência
CVE-2026-6858
Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS
41RISCO
abrir
Referência
CVE-2026-4259
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
41RISCO
abrir
Referência
CVE-2026-4110
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
33RISCO
abrir
Referência
CVE-2026-10530
Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
33RISCO
abrir
Referência
CVE-2026-13592
liftoff-sr CIPster EtherNet IP Message append out-of-bounds write
33RISCO
abrir
Referência
CVE-2026-13591
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
28RISCO
abrir
Referência
CVE-2026-13590
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
33RISCO
abrir
Referência
CVE-2026-13589
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
33RISCO
abrir
Referência
CVE-2026-34112
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
48RISCO
abrir
Referência
CVE-2026-13588
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
33RISCO
abrir
Referência
CVE-2026-13587
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
33RISCO
abrir
Referência
CVE-2026-13583
Edimax EW-7478APC POST Request formUSBFolder buffer overflow
41RISCO
abrir
Referência
CVE-2026-10811
itsourcecode Fees Management System receipt.php sql injection
33RISCO
abrir
Referência
CVE-2026-10550
elunez eladmin Application Deployment App.java command injection
33RISCO
abrir
Referência
CVE-2026-10548
NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication
33RISCO
abrir
Referência
CVE-2026-10301
itsourcecode Fees Management System index.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-10295
SourceCodester Customer Review App review_app.py get_all_reviews denial of service
33RISCO
abrir
Referência
CVE-2026-10292
UTT HiPER 1200GW formTaskEdit strcpy stack-based overflow
41RISCO
abrir
Referência
CVE-2026-10290
code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql injection
33RISCO
abrir
Referência
CVE-2026-10289
code-projects Hotel and Tourism Reservation System tour.php cross site scripting
33RISCO
abrir
Referência
CVE-2018-8467
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
Referência
CVE-2026-12189
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
33RISCO
abrir
Referência
CVE-2026-12187
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
41RISCO
abrir
Referência
CVE-2026-12186
GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection
41RISCO
abrir
Referência
CVE-2025-15546
Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition
33RISCO
abrir
Referência
CVE-2026-12174
D-Link DCS-935L HTTP rhea snprintf format string
41RISCO
abrir
Referência
CVE-2026-25557
Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter
33RISCO
abrir
Referência
CVE-2004-0798
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RISCO
abrir
anteriorpágina 485 / 747próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.