Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8.195Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.334 exploits
GitHub PoC★ 1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RISCO
abrir ↗GitHub PoC★ 1
yugo-eliatrope/test-cve-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 7
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Next.js Acceso no autorizado CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
Azure Storage Resource Provider Spoofing Vulnerability
48RISCO
abrir ↗GitHub PoC★ 53
yoshino-s/CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Check if a username is valid on the SSH server by attempting an authentication. The server response will indicate whether the username exists.
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗GitHub PoC★ 9
Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 5
PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 2
PowerShell script to test if a web app is vulnerable to CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 3
script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
A root exploit for CVE-2022-0847 (Dirty Pipe)
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 1
PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios d'attaque, analyse des risques et serveur Express.js de test.
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗GitHub PoC★ 1
POC for CVE-2023-30258-RCE by n0o0b
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗GitHub PoC
CVE-2025-22912
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RISCO
abrir ↗GitHub PoC
somatrasss/CVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir ↗GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.