Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
GitHub PoC10
CVE-2025-30208-EXP 任意文件读取
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC
CVE-2025-30208 任意文件读取漏洞快速验证
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC196
CVE-2025-30208-EXP
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30567HIGH26 mar 2025
WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
56RIESGO
abrir
GitHub PoC48
全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC248
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
CVE-2025-1097HIGH26 mar 2025
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RIESGO
abrir
GitHub PoC
Detection and exploitation scripts for CVE-2024-4956
CVE-2024-4956HIGH26 mar 2025
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC4
PoC of CVE-2025-1974, modified from the world-first PoC~
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC7
Poc for Ingress RCE
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
Next.js Acceso no autorizado CVE-2025-29927
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
A touch of security
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
New nuclei CVE
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
yugo-eliatrope/test-cve-2025-29927
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC8
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
CVE-2025-29927CRITICAL26 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
PoC
CVE-2025-30216CRITICAL26 mar 2025
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
48RIESGO
abrir
GitHub PoC2
EPICOR HCM Unauthenticated Blind SQL Injection CVE-2025-22953
CVE-2025-22953CRITICAL26 mar 2025
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC
48RIESGO
abrir
GitHub PoC
CVE-2025-22912
CVE-2025-22912CRITICAL25 mar 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RIESGO
abrir
GitHub PoC2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
CVE-2025-29972CRITICAL25 mar 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RIESGO
abrir
anteriorpágina 289 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.