Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
22.266 exploits
Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISCO
abrir
Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISCO
abrir
Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir
Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir
Referência
CVE-2017-17633
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISCO
abrir
Referência
CVE-2017-17633
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISCO
abrir
ReferênciaVexDay Proof
BitDefender - Module pdf.xmd Infinite Loop Denial of Service (PoC)
CVE-2008-5409doswindows
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGu
28RISCO
abrir
Referência
CVE-2010-3458
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attack
23RISCO
abrir
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir
ReferênciaVexDay Proof
yahoo answers - 'id' SQL Injection
CVE-2008-5490webappsphp
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Referência
CVE-2010-3458
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attack
23RISCO
abrir
Referência
CVE-2026-9517
hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control
33RISCO
abrir
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir
ReferênciaVexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
CVE-2008-5491webappsphp
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
CVE-2008-5492doswindows
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RISCO
abrir
Referência
CVE-2010-3462
Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly
23RISCO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RISCO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RISCO
abrir
Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISCO
abrir
Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISCO
abrir
Referência
CVE-2017-17639
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Referência
CVE-2021-47926
WordPress Contact Form to Email 1.3.24 Stored XSS
33RISCO
abrir
Referência
CVE-2021-47925
CMDBuild 3.3.2 Multiple Stored Cross-Site Scripting
33RISCO
abrir
Referência
CVE-2021-47924
WordPress Plugin Ultimate Product Catalogue 5.8.2 Stored XSS via price
33RISCO
abrir
Referência
CVE-2017-17639
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir
Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISCO
abrir
anteriorpágina 433 / 743próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.