Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
13.618 exploits
GitHub PoC
Sigma Rule for CVE-2025–29927 Detection
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC6
CVE-2025-29927 lab
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache Commons Text versions < 1.10.
CVE-2022-4288924 mar 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
Next.Js 权限绕过漏洞(CVE-2025-29927)
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC3
CVE-2025-29927 Proof of Concept
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
ejaboz/cve-2024-24919
CVE-2024-24919HIGHsob ataqueransomware24 mar 2025
Information disclosure
100RISCO
abrir
GitHub PoC38
zhuowei/CVE-2025-27363-proof-of-concept
CVE-2025-27363HIGHsob ataque23 mar 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISCO
abrir
GitHub PoC15
Next.js PoC for CVE-2025-29927
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC19
A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC9
Authorization Bypass in Next.js Middleware
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
Writeup and POC for CVE-2022-23134
CVE-2022-23134LOWsob ataque23 mar 2025
Possible view of the setup pages by unauthenticated users if config file already exists
95RISCO
abrir
GitHub PoC4
Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC14
lirantal/vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
ticofookfook/poc-nextjs-CVE-2025-29927
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC99
CVE-2025-29927 Proof of Concept
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Jenkins RCE Arbitrary File Read CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware23 mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC20
Proof-of-Concept for Authorization Bypass in Next.js Middleware
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
CVE-2024-49668CRITICAL22 mar 2025
WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC9
Otsmane-Ahmed/CVE-2025-2620-poc
CVE-2025-2620CRITICAL22 mar 2025
D-Link DAP-1620 Authentication storage mod_graph_auth_uri_handler stack-based overflow
48RISCO
abrir
GitHub PoC1
A PoC for CVE-2025-24813
CVE-2025-24813CRITICALsob ataque22 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
CVE-2024-49653CRITICAL22 mar 2025
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC1
A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2 server by analyzing authentication responses.
CVE-2018-15473MEDIUM22 mar 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
Verify Next.js CVE-2025-29927 on Netlify not vulnerable
CVE-2025-29927CRITICAL22 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC4
Next.js Middleware Authorization Bypass
CVE-2025-29927CRITICAL22 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
CVE-2024-52375CRITICAL22 mar 2025
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC2
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
CVE-2025-23922CRITICAL21 mar 2025
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
Proof-of-concept for In invoke-ai/invokeai version v5.0.2 Arbitrary File Deletion.
CVE-2024-11042CRITICAL21 mar 2025
Arbitrary File Delete in invoke-ai/invokeai
48RISCO
abrir
GitHub PoC
wilss0n/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware21 mar 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC4
CVE-2025-24813 Apache Tomcat RCE Proof of Concept (PoC)
CVE-2025-24813CRITICALsob ataque21 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
anteriorpágina 172 / 454próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.