Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
22.721 exploits
Referência
CVE-2018-10068
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
CVE-2006-2372remotewindows
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RISCO
abrir
Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir
Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir
Referência
CVE-2026-16959
Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
33RISCO
abrir
Referência
CVE-2026-16576
Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API
41RISCO
abrir
Referência
CVE-2026-16575
Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint
33RISCO
abrir
Referência
CVE-2026-13736
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
33RISCO
abrir
Referência
CVE-2026-77392
SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser sql injection
33RISCO
abrir
Referência
CVE-2026-14287
TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass
33RISCO
abrir
Referência
CVE-2026-14196
WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR
33RISCO
abrir
Referência
CVE-2026-13175
Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
33RISCO
abrir
Referência
CVE-2026-12983
Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
41RISCO
abrir
Referência
CVE-2026-11565
Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
41RISCO
abrir
Referência
CVE-2026-76048
SourceCodester Simple Online Food Ordering System ajax.php login sql injection
33RISCO
abrir
Referência
CVE-2026-76014
BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference
33RISCO
abrir
Referência
CVE-2026-75985
TRENDnet Router ping.cgi command injection
33RISCO
abrir
Referência
CVE-2026-17533
All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
41RISCO
abrir
Referência
CVE-2026-16985
Squeeze < 1.7.12 - Author+ Arbitrary File Upload
41RISCO
abrir
Referência
CVE-2026-16949
Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
33RISCO
abrir
Referência
CVE-2026-14941
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
33RISCO
abrir
Referência
CVE-2026-17012
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
33RISCO
abrir
Referência
CVE-2026-18666
Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
33RISCO
abrir
Referência
CVE-2026-18465
WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion
33RISCO
abrir
Referência
CVE-2026-18464
WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service
41RISCO
abrir
Referência
CVE-2026-18032
WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass
41RISCO
abrir
Referência
CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
48RISCO
abrir
Referência
CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
41RISCO
abrir
Referência
CVE-2026-10599
Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
41RISCO
abrir
anteriorpágina 726 / 758próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.