Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8.617Nuclei 4.257Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.233 exploits
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISCO
abrir ↗Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISCO
abrir ↗Referência
CVE-2010-3483
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISCO
abrir ↗Referência✓ VexDay Proof
Post Affiliate Pro 3 - 'umprof_status' Blind SQL Injection
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2017-17870
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISCO
abrir ↗Referência✓ VexDay Proof
Active Time Billing 3.2 - Authentication Bypass
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
Lito Lite CMS - 'cid' SQL Injection
SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
CMS Made Simple 1.4.1 - Local File Inclusion
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Myiosoft EasyBookMarker 4 - 'Parent' SQL Injection
SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote at
23RISCO
abrir ↗Referência
CVE-2017-17875
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISCO
abrir ↗Referência
CVE-2026-9438
yashpokharna2555 StudentManagementSystem courseDel.php resource injection
33RISCO
abrir ↗Referência✓ VexDay Proof
Kwalbum 2.0.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root,
23RISCO
abrir ↗Referência✓ VexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISCO
abrir ↗Referência✓ VexDay Proof
StormBoard 1.0.1 - SQL Injection
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência
CVE-2017-18078
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RISCO
abrir ↗Referência
CVE-2017-18078
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RISCO
abrir ↗Referência
CVE-2010-4982
SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attacker
23RISCO
abrir ↗Referência✓ VexDay Proof
ASPired2Quote - Remote Database Disclosure
The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allow
23RISCO
abrir ↗Referência✓ VexDay Proof
Discussion Web 4 - Remote Database Disclosure
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_registration_detailed 4.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (
23RISCO
abrir ↗Referência✓ VexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RISCO
abrir ↗Referência✓ VexDay Proof
4Images 1.7.x - 'search.php' SQL Injection
SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche Directory - Database Disclosure
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RISCO
abrir ↗Referência
CVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RISCO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche Articles - Database Disclosure
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.