Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
22.549 exploits
Referência
CVE-2014-4492
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RISCO
abrir ↗Referência
CVE-2014-4511
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RISCO
abrir ↗Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISCO
abrir ↗Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISCO
abrir ↗Referência
CVE-2009-4386
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe
23RISCO
abrir ↗Referência
CVE-2009-4423
SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência
CVE-2009-4432
SQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência
CVE-2015-4877
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RISCO
abrir ↗Referência
CVE-2026-59109
Zalktis: SQL injection via partner-controlled fields in imported e-invoices
41RISCO
abrir ↗Referência
CVE-2026-14332
Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
33RISCO
abrir ↗Referência
CVE-2026-19088
ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication
33RISCO
abrir ↗Referência
CVE-2026-18945
WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation
41RISCO
abrir ↗Referência
CVE-2026-14213
Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
28RISCO
abrir ↗Referência
CVE-2026-14182
Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass
48RISCO
abrir ↗Referência
CVE-2026-13610
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISCO
abrir ↗Referência
CVE-2026-13328
TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification
33RISCO
abrir ↗Referência
CVE-2026-18391
WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection
48RISCO
abrir ↗Referência
CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir ↗Referência
CVE-2026-18230
WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter
41RISCO
abrir ↗Referência
CVE-2026-18057
Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection
41RISCO
abrir ↗Referência
CVE-2026-18049
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo
41RISCO
abrir ↗Referência
CVE-2026-69112
Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map
33RISCO
abrir ↗Referência
CVE-2026-71966
CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer
41RISCO
abrir ↗Referência
CVE-2026-71964
CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload
41RISCO
abrir ↗Referência
CVE-2026-71962
Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.