Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.618 exploits
GitHub PoC
0xPb1/Next.js-CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHsob ataque25 mar 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios d'attaque, analyse des risques et serveur Express.js de test.
CVE-2024-4367MEDIUM25 mar 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC3
script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
0xcucumbersalad/cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
0xPThree/next.js_cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
PowerShell script to test if a web app is vulnerable to CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.
CVE-2024-21413CRITICALsob ataque25 mar 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC5
PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
somatrasss/CVE-2025-29306
CVE-2025-29306CRITICAL25 mar 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir
GitHub PoC2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
CVE-2025-29972CRITICAL25 mar 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RISCO
abrir
GitHub PoC1
POC for CVE-2023-30258-RCE by n0o0b
CVE-2023-30258CRITICAL25 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
GitHub PoC
jeymo092/cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC9
Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2025-22912
CVE-2025-22912CRITICAL25 mar 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RISCO
abrir
GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
CVE-2024-31114CRITICAL25 mar 2025
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
ejaboz/cve-2024-24919
CVE-2024-24919HIGHsob ataqueransomware24 mar 2025
Information disclosure
100RISCO
abrir
GitHub PoC1
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
CVE-2024-51793CRITICAL24 mar 2025
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC90
CVE-2025-1974
CVE-2025-1974CRITICAL24 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC6
CVE-2025-29927 lab
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC4
Session Exploit
CVE-2025-24813CRITICALsob ataque24 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC4
CVE-2025-29927 Exploit Checker
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC5
Demo for Next.js middleware bypass - CVE-2025-29927
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2002-0082
CVE-2002-008224 mar 2025
The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly
28RISCO
abrir
GitHub PoC3
CVE-2025-29927 Proof of Concept
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache Commons Text versions < 1.10.
CVE-2022-4288924 mar 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC2
Next.js 中间件授权绕过漏洞测试环境 (CVE-2025-29927)
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC7
A playground to test the RCE exploit for tomcat CVE-2025-24813
CVE-2025-24813CRITICALsob ataque24 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
anteriorpágina 171 / 454próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.