Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8.649Nuclei 4.283Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.367 exploits
Referência
CVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17626
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17626
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISCO
abrir ↗Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISCO
abrir ↗Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISCO
abrir ↗Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISCO
abrir ↗Referência
CVE-2026-58053
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
48RISCO
abrir ↗Referência
CVE-2026-58052
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
33RISCO
abrir ↗Referência✓ VexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência
CVE-2017-17637
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
Pictures Rating - 'index.php?msgid' SQL Injection
SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência
CVE-2007-3808
SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência
CVE-2017-17637
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISCO
abrir ↗Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft DirectX SAMI File Parsing - Remote Stack Overflow
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISCO
abrir ↗Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
A-shop 0.70 - Remote File Deletion
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Referência✓ VexDay Proof
LinkedIn Toolbar 3.0.2.1098 - Remote Buffer Overflow
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Explorer - '.GIF' Image Denial of Service
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certa
28RISCO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.7/5.2.3 - MySQL/MySQLi 'Safe_Mode' Bypass
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass
28RISCO
abrir ↗Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
Envolution 1.1.0 - 'topic' SQL Injection
SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to
23RISCO
abrir ↗Referência
CVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.