Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.580exploits catalogados
37.336CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.790GitHub PoC 15.371VulnCheck XDB 9.019Nuclei 4.416Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.375 exploits
GitHub PoC
CVE-2009-1151, phpMyAdmin의 set.up
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir ↗GitHub PoC★ 1
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd and /etc/shadow. POC
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir ↗GitHub PoC★ 9
IngressNightmare-PoC: (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) PoC ,One-click script 。 一键脚本
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISCO
abrir ↗GitHub PoC★ 1
This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813. It allow you to easily test the vulnerability on any version of Apache Tomcat
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
cve-2022-26134 atlassia Confluence Data Center2016 server OGNL %[...}
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC
Next.js CVE-2025-29927 demonstration
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
cesarbtakeda/Windows-Explorer-CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
dustblessnotdust/CVE-2024-25180
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf
48RISCO
abrir ↗GitHub PoC★ 2
This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Sornphut/CVE-2023-7028-GitLab
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir ↗GitHub PoC★ 1
Here is a simple but effective exploit for CVE-2025-29927.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISCO
abrir ↗GitHub PoC★ 3
Create lab for CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISCO
abrir ↗GitHub PoC★ 92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 3
CVE-2025-29927: Next.js Middleware Exploit
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
This repository is for educational and research purposes.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-30208 ViteVulnScanner
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗GitHub PoC★ 1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗GitHub PoC★ 11
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 2
Next.js CVE-2025-29927 Vulnerability Scanner
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
IngressNightmare (CVE-2025-1974)
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.