Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.618 exploits
GitHub PoC★ 25
A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC★ 4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 1
rubbxalc/CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC★ 35
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
CVE-2025-30208 检测工具。python script && nuclei template
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
Next.js Acceso no autorizado CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 10
CVE-2025-30208-EXP 任意文件读取
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 8
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
yugo-eliatrope/test-cve-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 48
全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RISCO
abrir ↗GitHub PoC★ 4
PoC of CVE-2025-1974, modified from the world-first PoC~
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 2
EPICOR HCM Unauthenticated Blind SQL Injection CVE-2025-22953
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC
48RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 248
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISCO
abrir ↗GitHub PoC
PoC
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
48RISCO
abrir ↗GitHub PoC★ 97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
Detection and exploitation scripts for CVE-2024-4956
Nexus Repository 3 - Path Traversal
61RISCO
abrir ↗GitHub PoC
The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
POC for CVE-2023-30258-RCE by n0o0b
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.