Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.060exploits catalogados
35.302CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8.607Nuclei 4.257Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.175 exploits
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISCO
abrir ↗Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir ↗Referência
CVE-2026-49136
Banana Slides 0.4.0 Path Traversal via generate_image() in ai_service.py
21RISCO
abrir ↗Referência
CVE-2026-43624
F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()
21RISCO
abrir ↗Referência
CVE-2026-43623
microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header()
21RISCO
abrir ↗Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RISCO
abrir ↗Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RISCO
abrir ↗Referência
CVE-2010-3428
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
wPortfolio 0.3 - Admin Password Changing
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RISCO
abrir ↗Referência
CVE-2017-17624
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISCO
abrir ↗Referência✓ VexDay Proof
AirvaeCommerce 3.0 - 'pid' SQL Injection
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência
CVE-2026-10252
itsourcecode Online House Rental System manage_tenant.php sql injection
33RISCO
abrir ↗Referência
CVE-2017-17624
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISCO
abrir ↗Referência✓ VexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RISCO
abrir ↗Referência
CVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RISCO
abrir ↗Referência
CVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17626
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17626
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISCO
abrir ↗Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISCO
abrir ↗Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir ↗Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.