Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
22.233 exploits
Referência
CVE-2017-15976
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-200
23RISCO
abrir
Referência
CVE-2026-10824
Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion
33RISCO
abrir
Referência
CVE-2026-10086
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISCO
abrir
ReferênciaVexDay Proof
AvailScript Jobs Portal Script - 'jid' SQL Injection
CVE-2008-4373webappsphp
SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
AvailScript Classmate Script - 'viewprofile.php' SQL Injection
CVE-2008-4375webappsphp
SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitr
23RISCO
abrir
Referência
CVE-2017-15978
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
23RISCO
abrir
ReferênciaVexDay Proof
MDaemon POP3 Server < 9.06 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-4364doswindows
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RISCO
abrir
ReferênciaVexDay Proof
VistaBB 2.x - 'functions_mod_user.php' Remote File Inclusion
CVE-2006-4365webappsphp
Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2017-15979
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
23RISCO
abrir
Referência
CVE-2017-15980
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
23RISCO
abrir
ReferênciaVexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
CVE-2006-4532webappsphp
PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and ear
23RISCO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Share Zone - 'id' SQL Injection
CVE-2008-4468webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQ
23RISCO
abrir
Referência
CVE-2026-8157
Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation
41RISCO
abrir
Referência
CVE-2026-7859
Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media
33RISCO
abrir
ReferênciaVexDay Proof
CMS Frogss 0.4 - 'podpis' SQL Injection
CVE-2006-4536webappsphp
SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
CVE-2006-4586webappsphp
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticat
23RISCO
abrir
ReferênciaVexDay Proof
Yourownbux 4.0 - 'cookie' SQL Injection
CVE-2008-4492webappsphp
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2017-16356
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft PicturePusher - ActiveX Cross-Site Arbitrary File Upload
CVE-2008-4493remotewindows
Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Editio
28RISCO
abrir
ReferênciaVexDay Proof
TorrentTrader Classic 1.04 - Blind SQL Injection
CVE-2008-4494webappsphp
SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
Built2Go PHP Realestate 1.5 - 'event_detail.php' SQL Injection
CVE-2008-4497webappsphp
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
TikiWiki 1.9 Sirius - 'jhot.php' Remote Command Execution
CVE-2006-4602webappsphp
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISCO
abrir
ReferênciaVexDay Proof
PHP Autos 2.9.1 - 'catid' SQL Injection
CVE-2008-4498webappsphp
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Referência
CVE-2026-9442
Edimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow
41RISCO
abrir
Referência
CVE-2017-16781
The installer in MyBB before 1.8.13 has XSS.
23RISCO
abrir
Referência
CVE-2017-16836
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via
23RISCO
abrir
ReferênciaVexDay Proof
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
CVE-2008-4572doswindows
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
ReferênciaVexDay Proof
MunzurSoft Wep Portal W3 - 'kat' SQL Injection
CVE-2008-4573webappsasp
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Ayco Okul Portali - 'linkid' SQL Injection
CVE-2008-4574webappsasp
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
Chilkat FTP ActiveX 2.0 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4583remotewindows
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to over
23RISCO
abrir
anteriorpágina 413 / 742próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.