Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
22.549 exploits
Referência
CVE-2026-18934
RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Deletion
33RISCO
abrir ↗Referência
CVE-2026-16949
Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
33RISCO
abrir ↗Referência
CVE-2026-14941
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
33RISCO
abrir ↗Referência
CVE-2026-14860
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
33RISCO
abrir ↗Referência
CVE-2026-14206
HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
41RISCO
abrir ↗Referência
CVE-2026-13701
Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
33RISCO
abrir ↗Referência
CVE-2026-13600
AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
41RISCO
abrir ↗Referência
CVE-2026-13170
Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
41RISCO
abrir ↗Referência
CVE-2026-12971
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
28RISCO
abrir ↗Referência
CVE-2026-17018
CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
33RISCO
abrir ↗Referência
Sphider Search Engine - Multiple Vulnerabilities
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
28RISCO
abrir ↗Referência
CVE-2026-17010
Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
33RISCO
abrir ↗Referência
CVE-2026-17016
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
28RISCO
abrir ↗Referência
CVE-2014-5112
maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacha
23RISCO
abrir ↗Referência
CVE-2014-5115
Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname
23RISCO
abrir ↗Referência
CVE-2026-17012
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
33RISCO
abrir ↗Referência
CVE-2015-6827
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentica
23RISCO
abrir ↗Referência
CVE-2015-6923
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RISCO
abrir ↗Referência
CVE-2015-6923
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RISCO
abrir ↗Referência
CVE-2026-70637
LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
41RISCO
abrir ↗Referência
CVE-2010-0373
SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISCO
abrir ↗Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISCO
abrir ↗Referência
CVE-2026-19010
TinyAGI Message API Endpoint index.ts processMessage authorization
33RISCO
abrir ↗Referência
CVE-2026-19009
TinyAGI Message API Endpoint response.ts collectFiles file inclusion
33RISCO
abrir ↗Referência
CVE-2026-19008
mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
33RISCO
abrir ↗Referência
CVE-2026-19007
mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.