Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
22.266 exploits
Referência
CVE-2026-10875
projectworlds Online Art Gallery Shop Project adminHome.ph sql injection
33RISCO
abrir
Referência
CVE-2026-10874
projectworlds Online Art Gallery Shop Project adminHome.php sql injection
33RISCO
abrir
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISCO
abrir
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISCO
abrir
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
ReferênciaVexDay Proof
Mole Group Pizza - 'manufacturers_id' SQL Injection
CVE-2008-5046webappsphp
SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Mole Group Rental Script - Authentication Bypass
CVE-2008-5047webappsphp
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RISCO
abrir
ReferênciaVexDay Proof
Anti-Keylogger Elite 3.3.0 - 'AKEProtect.sys' Local Privilege Escalation
CVE-2008-5049localwindows
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other version
23RISCO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RISCO
abrir
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISCO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISCO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISCO
abrir
Referência
CVE-2010-3467
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial modul
23RISCO
abrir
ReferênciaVexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
CVE-2008-5600webappsphp
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows re
23RISCO
abrir
Referência
CVE-2010-3467
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial modul
23RISCO
abrir
Referência
CVE-2010-3481
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allo
23RISCO
abrir
ReferênciaVexDay Proof
A-Blog 2.0 - Multiple Remote File Inclusions
CVE-2006-5135webappsphp
Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via
23RISCO
abrir
ReferênciaVexDay Proof
User Engine Lite ASP - 'users.mdb' Database Disclosure
CVE-2008-5601webappsphp
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RISCO
abrir
ReferênciaVexDay Proof
Natterchat 1.12 - Database Disclosure
CVE-2008-5602webappsasp
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
ASPTicker 1.0 - Remote Database Disclosure
CVE-2008-5603webappsasp
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISCO
abrir
Referência
CVE-2017-17737
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diag
23RISCO
abrir
Referência
CVE-2017-17738
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools
23RISCO
abrir
Referência
CVE-2017-17752
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code execute
23RISCO
abrir
Referência
CVE-2026-32847
DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py
21RISCO
abrir
Referência
CVE-2017-17849
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISCO
abrir
Referência
CVE-2017-17849
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISCO
abrir
Referência
CVE-2010-3483
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISCO
abrir
anteriorpágina 435 / 743próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.