Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.721 exploits
Referência
CVE-2026-12971
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
28RISCO
abrir ↗Referência
CVE-2018-14059
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RISCO
abrir ↗Referência✓ VexDay Proof
MySQL Commander 2.7 - 'home' Remote File Inclusion
PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when regis
23RISCO
abrir ↗Referência✓ VexDay Proof
JGBBS 3.0beta1 - 'search.asp?author' SQL Injection
SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência
CVE-2017-17571
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
23RISCO
abrir ↗Referência
CVE-2017-17572
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
23RISCO
abrir ↗Referência
CVE-2017-7293
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RISCO
abrir ↗Referência
CVE-2017-7310
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RISCO
abrir ↗Referência
CVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RISCO
abrir ↗Referência
CVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RISCO
abrir ↗Referência
CVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RISCO
abrir ↗Referência
CVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RISCO
abrir ↗Referência
CVE-2026-19192
DeepCool DisplayService DeepCoolDisplayService.exe access control
41RISCO
abrir ↗Referência
CVE-2017-17575
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RISCO
abrir ↗Referência
CVE-2017-17576
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RISCO
abrir ↗Referência
CVE-2017-17576
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RISCO
abrir ↗Referência
CVE-2017-17577
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RISCO
abrir ↗Referência
CVE-2017-17577
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RISCO
abrir ↗Referência
CVE-2017-17578
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RISCO
abrir ↗Referência
CVE-2017-17578
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RISCO
abrir ↗Referência
CVE-2026-18897
UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow
41RISCO
abrir ↗Referência✓ VexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Module splattforum 4.0 RC1 - Local File Inclusion
Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allo
23RISCO
abrir ↗Referência
CVE-2017-17594
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
23RISCO
abrir ↗Referência
CVE-2017-17594
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
23RISCO
abrir ↗Referência
CVE-2017-17595
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RISCO
abrir ↗Referência
CVE-2017-17596
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
23RISCO
abrir ↗Referência
CVE-2017-17596
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
23RISCO
abrir ↗Referência
CVE-2017-17598
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
23RISCO
abrir ↗Referência
CVE-2017-17601
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.