Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8.663Nuclei 4.287Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.407 exploits
Referência✓ VexDay Proof
Vbgooglemap Hotspot Edition 1.0.3 - SQL Injection
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2018-6584
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
23RISCO
abrir ↗Referência✓ VexDay Proof
Pilot Group eTraining - 'news_read.php' SQL Injection
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência
CVE-2018-6604
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RISCO
abrir ↗Referência✓ VexDay Proof
Joovili 3.0 - Multiple SQL Injections
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex
23RISCO
abrir ↗Referência✓ VexDay Proof
212Cafe Board 0.07 - 'qID' SQL Injection
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JPad 1.0 - (Authenticated) SQL Injection
SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrar
23RISCO
abrir ↗Referência
CVE-2018-6606
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Lance 1.52 - 'catid' SQL Injection
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
Post Comments 3.0 - Insecure Cookie Handling
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISCO
abrir ↗Referência✓ VexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web scri
23RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin WP Comment Remix 1.4.3 - SQL Injection
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote
23RISCO
abrir ↗Referência✓ VexDay Proof
KVIrc 3.4.0 - Virgo Remote Format String (PoC)
Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC UR
23RISCO
abrir ↗Referência
Joomla! Component JSP Tickets 1.1 - SQL Injection
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti
23RISCO
abrir ↗Referência✓ VexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laborato
23RISCO
abrir ↗Referência✓ VexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_extplorer 2.0.0 RC2 - Local Directory Traversal
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote
43RISCO
abrir ↗Referência
CVE-2008-4765
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbi
23RISCO
abrir ↗Referência✓ VexDay Proof
QuestCMS - Cross-Site Scripting / Directory Traversal / SQL Injection
Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via
23RISCO
abrir ↗Referência✓ VexDay Proof
Dream4 Koobi Pro 6.25 Showimages - 'galid' SQL Injection
SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência✓ VexDay Proof
TugZip 3.00 Archiver - '.zip' Local Buffer Overflow
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISCO
abrir ↗Referência✓ VexDay Proof
e107 Plugin alternate_profiles - 'id' SQL Injection
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
e107 Plugin EasyShop - 'category_id' Blind SQL Injection
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows r
35RISCO
abrir ↗Referência✓ VexDay Proof
Sepal SPBOARD 4.5 - 'board.cgi' Remote Command Execution
board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the fil
23RISCO
abrir ↗Referência
CVE-2026-19058
FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection
33RISCO
abrir ↗Referência
CVE-2026-13703
SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure
33RISCO
abrir ↗Referência
CVE-2026-13154
Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
41RISCO
abrir ↗Referência
CVE-2026-13153
Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint
41RISCO
abrir ↗Referência
CVE-2026-12713
WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.