Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
76.008 exploits
GitHub PoC★ 3
Create lab for CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISCO
abrir ↗GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-30208 ViteVulnScanner
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 3
CVE-2025-29927: Next.js Middleware Exploit
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
This repository is for educational and research purposes.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISCO
abrir ↗Exploit-DB
Litespeed Cache 6.5.0.1 - Authentication Bypass
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISCO
abrir ↗GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISCO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RISCO
abrir ↗Exploit-DB
CodeCanyon RISE CRM 3.7.0 - SQL Injection
CodeCanyon RISE Ultimate Project Manager save sql injection
38RISCO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RISCO
abrir ↗VulnCheck XDB
client-side
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take
53RISCO
abrir ↗Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RISCO
abrir ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗VulnCheck XDB
infoleak
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗GitHub PoC★ 2
Next.js CVE-2025-29927 Vulnerability Scanner
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 10
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
IngressNightmare (CVE-2025-1974)
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 1
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.