Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.152GitHub PoC 15.158VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
19.066 exploits
Exploit-DB✓ VexDay Proof
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Car Rental Script 2.0.4 - 'val' SQL Injection
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Resume Clone Script 2.0.5 - SQL Injection
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Professional Service Script 1.0 - 'service-list?city' SQL Injection
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'getrusage' Stack Leak Through struct Padding
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Vanguard 1.4 - SQL Injection
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Grubhub Clone 1.0 - 'keywords' SQL Injection
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Indiamart Clone 1.0 - 'token' / 'id' / 'c' SQL Injection
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Foodpanda Clone 1.0 - SQL Injection
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Freelancer Clone 1.0 - 'profile.php?u' SQL Injection
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Amazon Clone 1.0 - SQL Injection
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Groupon Clone 1.0 - 'id' SQL Injection
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid' SQL Injection
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.