Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2018-10068
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
CVE-2006-2372remotewindows
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RIESGO
abrir
Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Referência
CVE-2026-16959
Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
33RIESGO
abrir
Referência
CVE-2026-16576
Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API
41RIESGO
abrir
Referência
CVE-2026-16575
Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint
33RIESGO
abrir
Referência
CVE-2026-13736
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
33RIESGO
abrir
Referência
CVE-2026-77392
SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser sql injection
33RIESGO
abrir
Referência
CVE-2026-14287
TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass
33RIESGO
abrir
Referência
CVE-2026-14196
WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR
33RIESGO
abrir
Referência
CVE-2026-13175
Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
33RIESGO
abrir
Referência
CVE-2026-12983
Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
41RIESGO
abrir
Referência
CVE-2026-11565
Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
41RIESGO
abrir
Referência
CVE-2026-76048
SourceCodester Simple Online Food Ordering System ajax.php login sql injection
33RIESGO
abrir
Referência
CVE-2026-76014
BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference
33RIESGO
abrir
Referência
CVE-2026-75985
TRENDnet Router ping.cgi command injection
33RIESGO
abrir
Referência
CVE-2026-17533
All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
41RIESGO
abrir
Referência
CVE-2026-16985
Squeeze < 1.7.12 - Author+ Arbitrary File Upload
41RIESGO
abrir
Referência
CVE-2026-16949
Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
33RIESGO
abrir
Referência
CVE-2026-14941
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
33RIESGO
abrir
Referência
CVE-2026-17012
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
33RIESGO
abrir
Referência
CVE-2026-18666
Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
33RIESGO
abrir
Referência
CVE-2026-18465
WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion
33RIESGO
abrir
Referência
CVE-2026-18464
WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service
41RIESGO
abrir
Referência
CVE-2026-18032
WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass
41RIESGO
abrir
Referência
CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
48RIESGO
abrir
Referência
CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
41RIESGO
abrir
Referência
CVE-2026-10599
Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
41RIESGO
abrir
anteriorpágina 726 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.