Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
22.407 exploits
ReferênciaVexDay Proof
PHP Autos 2.9.1 - 'catid' SQL Injection
CVE-2008-4498webappsphp
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
IP Reg 0.4 - Blind SQL Injection
CVE-2008-4523webappsphp
SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Referência
CVE-2008-4525
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod recept - 'kat_id' SQL Injection
CVE-2008-4527webappsphp
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
pPIM 1.01 - 'notes.php' Local File Inclusion
CVE-2008-4528webappsphp
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
asiCMS alpha 0.208 - Multiple Remote File Inclusions
CVE-2008-4529webappsphp
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - 'xlacomments.asp' SQL Injection
CVE-2008-4569webappsasp
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Ayco Okul Portali - 'linkid' SQL Injection
CVE-2008-4574webappsasp
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
Chilkat FTP ActiveX 2.0 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4583remotewindows
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to over
23RISCO
abrir
ReferênciaVexDay Proof
Macrovision FlexNet DownloadManager - Insecure Methods
CVE-2008-4587remotewindows
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.
28RISCO
abrir
ReferênciaVexDay Proof
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
CVE-2008-4591webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote
23RISCO
abrir
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISCO
abrir
ReferênciaVexDay Proof
Real Estate Manager 1.01 - 'cat_id' SQL Injection
CVE-2008-4674webappsphp
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.3 - Remote Code Execution
CVE-2008-4687webappsphp
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4696remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RISCO
abrir
Referência
Joomla! Component Jimtawl 2.1.6 - Arbitrary File Upload
CVE-2018-6580webappsphp
Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true
35RISCO
abrir
Referência
CVE-2026-19383
saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload
33RISCO
abrir
ReferênciaVexDay Proof
Peachtree Accounting 2004 - 'PAWWeb11.ocx' ActiveX Insecure Method
CVE-2008-4699remotewindows
Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers
28RISCO
abrir
ReferênciaVexDay Proof
Vbgooglemap Hotspot Edition 1.0.3 - SQL Injection
CVE-2008-4706webappsphp
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute
23RISCO
abrir
Referência
CVE-2018-6584
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
23RISCO
abrir
ReferênciaVexDay Proof
Pilot Group eTraining - 'news_read.php' SQL Injection
CVE-2008-4709webappsphp
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2018-6604
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RISCO
abrir
ReferênciaVexDay Proof
Joovili 3.0 - Multiple SQL Injections
CVE-2008-4711webappsphp
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
212Cafe Board 0.07 - 'qID' SQL Injection
CVE-2008-4713webappsphp
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component JPad 1.0 - (Authenticated) SQL Injection
CVE-2008-4715webappsphp
SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrar
23RISCO
abrir
Referência
CVE-2018-6606
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Lance 1.52 - 'catid' SQL Injection
CVE-2008-4716webappsphp
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
Post Comments 3.0 - Insecure Cookie Handling
CVE-2008-4721webappsphp
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISCO
abrir
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4725remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web scri
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin WP Comment Remix 1.4.3 - SQL Injection
CVE-2008-4732webappsphp
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote
23RISCO
abrir
anteriorpágina 477 / 747próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.