Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
CVE-2017-1761211 dez 2017
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir
Exploit-DB
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
CVE-2017-1762211 dez 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISCO
abrir
Exploit-DB
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
CVE-2017-1762111 dez 2017
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RISCO
abrir
Exploit-DB
Professional Service Script 1.0 - 'service-list?city' SQL Injection
CVE-2017-1762511 dez 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISCO
abrir
Exploit-DB
Laundry Booking Script 1.0 - 'list?city' SQL Injection
CVE-2017-1761911 dez 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DB
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
CVE-2017-1761311 dez 2017
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISCO
abrir
Exploit-DB
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
CVE-2017-1762411 dez 2017
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISCO
abrir
Exploit-DB
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
CVE-2017-1762611 dez 2017
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir
Exploit-DB
Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
CVE-2017-1762011 dez 2017
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RISCO
abrir
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
CVE-2017-100040511 dez 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RISCO
abrir
Exploit-DB
Food Order Script 1.0 - 'list?city' SQL Injection
CVE-2017-1761411 dez 2017
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DB
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
CVE-2017-1761711 dez 2017
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISCO
abrir
Exploit-DB
Yoga Class Script 1.0 - 'list?city' SQL Injection
CVE-2017-1763011 dez 2017
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Exploit-DB
Linux Kernel 4.13 (Debian 9) - Local Privilege Escalation
CVE-2017-1699411 dez 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISCO
abrir
Exploit-DB
Linux Kernel - 'mincore()' Heap Page Disclosure (PoC)
CVE-2017-1699411 dez 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISCO
abrir
Exploit-DB
Readymade Video Sharing Script 3.2 - SQL Injection
CVE-2017-1762711 dez 2017
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RISCO
abrir
Exploit-DB
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
CVE-2017-1763611 dez 2017
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RISCO
abrir
Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
CVE-2017-1763511 dez 2017
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RISCO
abrir
Exploit-DB
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-1763411 dez 2017
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir
Exploit-DB
Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
CVE-2017-1763811 dez 2017
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISCO
abrir
Exploit-DB
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
CVE-2017-1762811 dez 2017
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISCO
abrir
Exploit-DB
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
CVE-2017-1763911 dez 2017
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Exploit-DB
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
CVE-2017-1763311 dez 2017
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISCO
abrir
Exploit-DB
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-1763211 dez 2017
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir
Exploit-DB
Resume Clone Script 2.0.5 - SQL Injection
CVE-2017-1764111 dez 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISCO
abrir
Exploit-DB
Basic Job Site Script 2.0.5 - SQL Injection
CVE-2017-1764211 dez 2017
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RISCO
abrir
Exploit-DB
Car Rental Script 2.0.4 - 'val' SQL Injection
CVE-2017-1763711 dez 2017
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISCO
abrir
Exploit-DB
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
CVE-2017-1762911 dez 2017
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RISCO
abrir
Exploit-DB
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
CVE-2017-1763111 dez 2017
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Exploit-DB
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
CVE-2017-1761511 dez 2017
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RISCO
abrir
anteriorpágina 113 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.