Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8.663Nuclei 4.287Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.407 exploits
Referência✓ VexDay Proof
Maian Search 1.1 - Insecure Cookie Handling
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir ↗Referência✓ VexDay Proof
Maian Guestbook 3.2 - Insecure Cookie Handling
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrat
23RISCO
abrir ↗Referência✓ VexDay Proof
Maian Uploader 4.0 - Insecure Cookie Handling
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrati
23RISCO
abrir ↗Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to
23RISCO
abrir ↗Referência✓ VexDay Proof
ShopCartDx 4.30 - 'pid' SQL Injection
SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir ↗Referência✓ VexDay Proof
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RISCO
abrir ↗Referência
CVE-2026-9512
Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection
33RISCO
abrir ↗Referência
CVE-2026-9511
Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
33RISCO
abrir ↗Referência
CVE-2026-9498
Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine
33RISCO
abrir ↗Referência✓ VexDay Proof
TubeGuru Video Sharing Script - 'UID' SQL Injection
SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execut
23RISCO
abrir ↗Referência
CVE-2018-5981
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISCO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISCO
abrir ↗Referência✓ VexDay Proof
phpArcadeScript 4 - 'cat' SQL Injection
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute a
23RISCO
abrir ↗Referência✓ VexDay Proof
cyberBB 0.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Ad Board - 'id' SQL Injection
SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
Banner Management Script - 'id' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Classifieds - 'category' SQL Injection
SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VM
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RISCO
abrir ↗Referência
CVE-2008-3765
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Referência✓ VexDay Proof
Quick Poll Script - 'id' SQL Injection
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Referência
CVE-2018-5982
SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= requ
23RISCO
abrir ↗Referência✓ VexDay Proof
SunShop Shopping Cart 4.1.4 - 'id' SQL Injection
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow r
23RISCO
abrir ↗Referência✓ VexDay Proof
Pars4U Videosharing 1.0 - Cross-Site Scripting / Blind SQL Injection
SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
Matterdaddy Market 1.1 - 'index.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow
23RISCO
abrir ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6i - Mms Protocol Handling Heap Overflow (PoC)
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i all
28RISCO
abrir ↗Referência✓ VexDay Proof
Crafty Syntax Live Help 2.14.6 - 'department' SQL Injection
Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to ex
23RISCO
abrir ↗Referência✓ VexDay Proof
Acoustica Mixcraft 4.2 - Universal Stack Overflow (SEH)
Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execut
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.