Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
22.549 exploits
Referência
CVE-2010-0373
SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrar
23RISCO
abrir
Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISCO
abrir
Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISCO
abrir
Referência
CVE-2026-19011
TinyAGI agents.ts buildSystemPrompt file inclusion
33RISCO
abrir
Referência
CVE-2026-19010
TinyAGI Message API Endpoint index.ts processMessage authorization
33RISCO
abrir
Referência
CVE-2026-19009
TinyAGI Message API Endpoint response.ts collectFiles file inclusion
33RISCO
abrir
Referência
CVE-2026-19008
mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
33RISCO
abrir
Referência
CVE-2026-19007
mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
33RISCO
abrir
Referência
CVE-2026-14204
Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF
33RISCO
abrir
Referência
CVE-2026-16537
Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
33RISCO
abrir
Referência
CVE-2026-18395
Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
33RISCO
abrir
Referência
CVE-2026-16065
Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
33RISCO
abrir
Referência
CVE-2026-14829
Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
41RISCO
abrir
Referência
CVE-2026-11588
EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation
33RISCO
abrir
Referência
CVE-2022-35914
CVE-2022-35914CRITICALsob ataque
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir
Referência
CVE-2009-5093
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RISCO
abrir
Referência
CVE-2015-8425
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
Referência
CVE-2026-14839
Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
41RISCO
abrir
Referência
CVE-2026-14823
Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
28RISCO
abrir
Referência
CVE-2026-14822
Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
33RISCO
abrir
Referência
CVE-2026-14561
Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
33RISCO
abrir
Referência
CVE-2026-14315
Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
33RISCO
abrir
Referência
CVE-2026-14292
WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
33RISCO
abrir
Referência
CVE-2026-14214
Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
28RISCO
abrir
Referência
CVE-2026-14195
Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
28RISCO
abrir
Referência
CVE-2026-13729
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
33RISCO
abrir
Referência
CVE-2026-13725
Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
41RISCO
abrir
Referência
CVE-2026-13604
Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
33RISCO
abrir
Referência
CVE-2026-13596
Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
48RISCO
abrir
Referência
CVE-2026-13329
WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
33RISCO
abrir
anteriorpágina 604 / 752próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.