Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
13.627 exploits
GitHub PoC★ 25
A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗GitHub PoC★ 1
rubbxalc/CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗GitHub PoC★ 2
Next.js CVE-2025-29927 Vulnerability Scanner
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 2
next.js CVE-2025-29927 vulnerability exploit
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 35
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗GitHub PoC★ 1
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
IngressNightmare (CVE-2025-1974)
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC★ 10
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC★ 4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC★ 1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RIESGO
abrir ↗GitHub PoC★ 48
全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC
CVE-2025-30208 任意文件读取漏洞快速验证
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC
PoC
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
48RIESGO
abrir ↗GitHub PoC★ 8
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 2
EPICOR HCM Unauthenticated Blind SQL Injection CVE-2025-22953
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC
48RIESGO
abrir ↗GitHub PoC★ 1
yugo-eliatrope/test-cve-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 4
PoC of CVE-2025-1974, modified from the world-first PoC~
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC★ 10
CVE-2025-30208-EXP 任意文件读取
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC
Next.js Acceso no autorizado CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.