Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
21.899 exploits
Referência
CVE-2026-7812
54yyyu code-mcp MCP Tool server.py git_operation command injection
33RISCO
abrir
Referência
CVE-2026-7811
54yyyu code-mcp MCP File server.py is_safe_path path traversal
33RISCO
abrir
Referência
CVE-2026-7741
CodeAstro Online Classroom studentlogin sql injection
33RISCO
abrir
Referência
CVE-2026-7725
PrefectHQ prefect GitRepository Pull storage.py argument injection
33RISCO
abrir
Referência
CVE-2026-7724
PrefectHQ prefect Webhook/Notification validate_restricted_url toctou
28RISCO
abrir
Referência
CVE-2020-6519
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy
28RISCO
abrir
Referência
CVE-2021-25155
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RISCO
abrir
Referência
CVE-2026-13597
QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover
48RISCO
abrir
Referência
CVE-2021-26084
CVE-2021-26084CRITICALsob ataqueransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
Referência
CVE-2026-16489
jsforce SFDX Connection Registry sfdx.js _execCommand os command injection
33RISCO
abrir
Referência
CVE-2026-64821
djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views
33RISCO
abrir
Referência
CVE-2026-64822
djangoSIGE 1.10 User Enumeration via ForgotPasswordView
33RISCO
abrir
Referência
CVE-2026-16447
D-Link DNS-320 multi_uploadify.php unrestricted upload
33RISCO
abrir
Referência
CVE-2026-14184
Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR
33RISCO
abrir
Referência
CVE-2026-14183
Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR
33RISCO
abrir
Referência
CVE-2026-13694
Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass
33RISCO
abrir
Referência
CVE-2026-13693
Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
33RISCO
abrir
Referência
CVE-2026-11767
CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form
41RISCO
abrir
Referência
CVE-2026-16329
D-Link DNS-320 uploadify.php unrestricted upload
33RISCO
abrir
Referência
CVE-2026-63767
ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ
48RISCO
abrir
Referência
CVE-2026-63768
cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State
33RISCO
abrir
Referência
CVE-2026-9833
Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
41RISCO
abrir
Referência
CVE-2026-11349
Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more
41RISCO
abrir
Referência
CVE-2026-10755
All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration
28RISCO
abrir
Referência
CVE-2026-10081
Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget
41RISCO
abrir
Referência
CVE-2026-16155
SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-16154
SourceCodester Class and Exam Timetabling System edit_room1.php sql injection
33RISCO
abrir
Referência
CVE-2026-16152
SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection
33RISCO
abrir
Referência
CVE-2026-16133
LiuMengxuan04 MiniCode mcp.ts child_process.spawn command injection
28RISCO
abrir
Referência
CVE-2026-16131
itsourcecode Hospital Management System prescriptionrecord.php sql injection
33RISCO
abrir
anteriorpágina 376 / 730próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.