Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
76.008 exploits
GitHub PoC35
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC1
rubbxalc/CVE-2025-24071
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC25
A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
Exploit-DB
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
CVE-2024-48120MEDIUMwebappsphp27 mar 2025
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma
33RISCO
abrir
GitHub PoC
CVE-2025-30208 检测工具。python script && nuclei template
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2017-5638CRITICALsob ataqueransomware27 mar 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
Heimd411/CVE-2025-29927-PoC
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM27 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMsob ataque27 mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-30349HIGH27 mar 2025
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL27 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
CVE-2019-9978MEDIUMsob ataque27 mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
liemkaka/CVE-2018-9206
CVE-2018-920627 mar 2025
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2025-30208 任意文件读取漏洞快速验证
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC10
CVE-2025-30208-EXP 任意文件读取
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
anteriorpágina 288 / 2.534próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.