Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.580exploits catalogados
37.336CVEs com exploração pública
24.695testados em laboratório
15.375 exploits
GitHub PoC
CVE-2009-1151, phpMyAdmin의 set.up
CVE-2009-1151CRITICALsob ataque30 mar 2025
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir
GitHub PoC1
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd and /etc/shadow. POC
CVE-2020-11651CRITICALsob ataque30 mar 2025
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC9
IngressNightmare-PoC: (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) PoC ,One-click script 。 一键脚本
CVE-2025-1097HIGH30 mar 2025
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISCO
abrir
GitHub PoC1
This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813. It allow you to easily test the vulnerability on any version of Apache Tomcat
CVE-2025-24813CRITICALsob ataque30 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
cve-2022-26134 atlassia Confluence Data Center2016 server OGNL %[...}
CVE-2022-26134CRITICALsob ataqueransomware30 mar 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
Next.js CVE-2025-29927 demonstration
CVE-2025-29927CRITICAL29 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
cesarbtakeda/Windows-Explorer-CVE-2025-24071
CVE-2025-24071MEDIUM29 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
dustblessnotdust/CVE-2024-25180
CVE-2024-25180CRITICAL29 mar 2025
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf
48RISCO
abrir
GitHub PoC2
This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.
CVE-2025-29927CRITICAL29 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Sornphut/CVE-2023-7028-GitLab
CVE-2023-7028CRITICALsob ataque29 mar 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir
GitHub PoC1
Here is a simple but effective exploit for CVE-2025-29927.
CVE-2025-29927CRITICAL29 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
CVE-2025-2775CRITICALsob ataque28 mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISCO
abrir
GitHub PoC3
Create lab for CVE-2025-24813
CVE-2025-24813CRITICALsob ataque28 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
CVE-2024-23897CRITICALsob ataqueransomware28 mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL28 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
CVE-2020-0618CRITICALsob ataqueransomware28 mar 2025
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISCO
abrir
GitHub PoC92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC3
CVE-2025-29927: Next.js Middleware Exploit
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
This repository is for educational and research purposes.
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
CVE-2025-30208 ViteVulnScanner
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
CVE-2025-30208 | Vite脚本
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL27 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
CVE-2019-9978MEDIUMsob ataque27 mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC7
CVE-2025-29927에 대한 설명 및 리서치
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC11
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC2
Next.js CVE-2025-29927 Vulnerability Scanner
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
IngressNightmare (CVE-2025-1974)
CVE-2025-1974CRITICAL27 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2021-44228CRITICALsob ataqueransomware27 mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
anteriorpágina 220 / 513próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.