Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.401exploits catalogados
35.511CVEs com exploração pública
24.695testados em laboratório
22.332 exploits
Referência
CVE-2026-15471
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
33RISCO
abrir
Referência
CVE-2026-16073
AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting
33RISCO
abrir
Referência
CVE-2026-15470
Eleveo Call Recording Software group.jsp improper authorization
33RISCO
abrir
Referência
CVE-2026-63093
Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
41RISCO
abrir
Referência
CVE-2026-11966
User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
33RISCO
abrir
Referência
CVE-2026-11961
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
41RISCO
abrir
Referência
CVE-2026-11575
PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
41RISCO
abrir
Referência
CVE-2026-10525
NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
33RISCO
abrir
Referência
CVE-2026-12492
Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
48RISCO
abrir
Referência
CVE-2026-12395
WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter
33RISCO
abrir
Referência
CVE-2022-50969
uBidAuction 2.0.1 mailingLog manage Reflected XSS
33RISCO
abrir
Referência
CVE-2022-50968
uBidAuction 2.0.1 auctions manage Reflected XSS
33RISCO
abrir
Referência
CVE-2022-50967
uBidAuction 2.0.1 tickets manage Reflected XSS
33RISCO
abrir
Referência
CVE-2022-50966
uBidAuction 2.0.1 news manage Reflected XSS
33RISCO
abrir
Referência
CVE-2022-50966
uBidAuction 2.0.1 news manage Reflected XSS
33RISCO
abrir
Referência
CVE-2026-7823
Totolink A8000RU cstecgi.cgi setAppFilterCfg os command injection
48RISCO
abrir
Referência
CVE-2026-7822
itsourcecode Courier Management System print_pdets.php sql injection
33RISCO
abrir
Referência
CVE-2026-7812
54yyyu code-mcp MCP Tool server.py git_operation command injection
33RISCO
abrir
Referência
CVE-2026-7811
54yyyu code-mcp MCP File server.py is_safe_path path traversal
33RISCO
abrir
Referência
CVE-2026-7741
CodeAstro Online Classroom studentlogin sql injection
33RISCO
abrir
Referência
CVE-2026-7725
PrefectHQ prefect GitRepository Pull storage.py argument injection
33RISCO
abrir
Referência
CVE-2026-7724
PrefectHQ prefect Webhook/Notification validate_restricted_url toctou
28RISCO
abrir
Referência
CVE-2020-6519
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy
28RISCO
abrir
Referência
CVE-2019-2729
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir
Referência
CVE-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
Referência
CVE-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
Referência
CVE-2026-34115
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php
48RISCO
abrir
Referência
CVE-2026-11794
Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
41RISCO
abrir
Referência
CVE-2026-11562
WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
33RISCO
abrir
Referência
CVE-2026-13582
Edimax EW-7478APC POST Request formUSBAccount buffer overflow
41RISCO
abrir
anteriorpágina 487 / 745próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.