Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.697 exploits
Referência
CVE-2026-16289
ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
33RISCO
abrir ↗Referência✓ VexDay Proof
YenerTurk Haber Script 1.0 - SQL Injection
SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2026-15254
Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode
33RISCO
abrir ↗Referência
CVE-2026-18582
mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap
33RISCO
abrir ↗Referência
CVE-2025-15675
Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
33RISCO
abrir ↗Referência
CVE-2026-16285
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
41RISCO
abrir ↗Referência
CVE-2026-16273
Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
33RISCO
abrir ↗Referência
CVE-2013-6881
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands vi
28RISCO
abrir ↗Referência
CVE-2016-4204
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir ↗Referência
CVE-2016-4206
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir ↗Referência
CVE-2026-13729
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
33RISCO
abrir ↗Referência
CVE-2026-13725
Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
41RISCO
abrir ↗Referência
CVE-2026-7238
code-projects Online Music Site AdminUpdateAlbum.php unrestricted upload
33RISCO
abrir ↗Referência
CVE-2026-7237
AgiFlow scaffold-mcp write-to-file Tool index.ts path traversal
33RISCO
abrir ↗Referência
CVE-2026-7234
BrowserOperator browser-operator-core server.js startsWith path traversal
33RISCO
abrir ↗Referência
CVE-2026-7233
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
33RISCO
abrir ↗Referência
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISCO
abrir ↗Referência
CVE-2010-5000
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute ar
23RISCO
abrir ↗Referência
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISCO
abrir ↗Referência
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISCO
abrir ↗Referência
CVE-2026-12966
Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
33RISCO
abrir ↗Referência
CVE-2025-15669
Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
33RISCO
abrir ↗Referência
CVE-2026-14827
Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
33RISCO
abrir ↗Referência
CVE-2026-65693
Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates
41RISCO
abrir ↗Referência
CVE-2026-66006
lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs
33RISCO
abrir ↗Referência
CVE-2026-66005
Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.