Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8.617Nuclei 4.257Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.233 exploits
Referência
CVE-2014-9347
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
Pre Shopping Mall 1.0 - SQL Injection
SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência
CVE-2014-2847
SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Cahier de texte 2.0 - 'lire.php' SQL Injection
Multiple SQL injection vulnerabilities in Cahier de texte 2.0 allow remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Referência
CVE-2017-10204
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISCO
abrir ↗Referência
CVE-2014-8359
Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
CMME 1.12 - Local File Inclusion / Cross-Site Scripting / Cross-Site Request Forgery/Download Backup/Make Directory
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web
23RISCO
abrir ↗Referência
CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗Referência
CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗Referência
Sitefinity 15.0 - Cross-Site Scripting (XSS)
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
33RISCO
abrir ↗Referência✓ VexDay Proof
UStore 1.0 - 'detail.asp' SQL Injection
SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Estate Agent Manager 1.3 - 'default.asp' Authentication Bypass
SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to exec
23RISCO
abrir ↗Referência
CVE-2015-4658
Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2010-4236
Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to
23RISCO
abrir ↗Referência
CVE-2014-9445
SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to exec
23RISCO
abrir ↗Referência
CVE-2009-4791
Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute a
23RISCO
abrir ↗Referência
CVE-2013-6767
Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary co
23RISCO
abrir ↗Referência
CVE-2013-6767
Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary co
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component MoSpray 18RC1 - Remote File Inclusion
PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php
23RISCO
abrir ↗Referência✓ VexDay Proof
vBulletin 3.6.4 - 'inlinemod.php?postids' SQL Injection
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, mi
23RISCO
abrir ↗Referência✓ VexDay Proof
NetVIOS 2.0 - 'page.asp' SQL Injection
SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência
CVE-2012-5334
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência
CVE-2016-1885
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RISCO
abrir ↗Referência
CVE-2016-1885
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RISCO
abrir ↗Referência
CVE-2026-8113
8421bit MiniClaw executeSkillScript kernel.ts isPathInside path traversal
33RISCO
abrir ↗Referência
CVE-2026-8112
8421bit MiniClaw kernel.ts executeCognitivePulse os command injection
33RISCO
abrir ↗Referência
CVE-2014-10019
Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Ga
23RISCO
abrir ↗Referência
CVE-2017-9150
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.