Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
13.334 exploits
GitHub PoC4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
IngressNightmare (CVE-2025-1974)
CVE-2025-1974CRITICAL27 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.
CVE-2025-1974CRITICAL27 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2017-5638CRITICALsob ataqueransomware27 mar 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
liemkaka/CVE-2018-9206
CVE-2018-920627 mar 2025
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
GitHub PoC3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL27 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC1
rubbxalc/CVE-2025-24071
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
CVE-2019-9978MEDIUMsob ataque27 mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC9
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC25
A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2021-44228CRITICALsob ataqueransomware27 mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC33
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
CVE-2025-30208 检测工具。python script && nuclei template
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC2
next.js CVE-2025-29927 vulnerability exploit
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
Next.js CVE-2025-29927 Vulnerability Scanner
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Heimd411/CVE-2025-29927-PoC
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC7
CVE-2025-29927에 대한 설명 및 리서치
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
A touch of security
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
PoC
CVE-2025-30216CRITICAL26 mar 2025
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
48RISCO
abrir
GitHub PoC97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Next.js Acceso no autorizado CVE-2025-29927
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC7
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
yugo-eliatrope/test-cve-2025-29927
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
New nuclei CVE
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
CVE-2024-12252CRITICAL26 mar 2025
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RISCO
abrir
anteriorpágina 161 / 445próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.