Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.629exploits catalogados
37.377CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.385VulnCheck XDB 9.019Nuclei 4.416Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.386 exploits
GitHub PoC★ 1
CVE-2025-30208 ViteVulnScanner
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗GitHub PoC★ 3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗GitHub PoC
CVE-2025-30208 检测工具。python script && nuclei template
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 11
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
liemkaka/CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir ↗GitHub PoC
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 1
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 35
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC★ 1
rubbxalc/CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC★ 2
Next.js CVE-2025-29927 Vulnerability Scanner
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 24
A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
IngressNightmare (CVE-2025-1974)
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
next.js CVE-2025-29927 vulnerability exploit
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 48
全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 10
CVE-2025-30208-EXP 任意文件读取
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
PoC
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
48RISCO
abrir ↗GitHub PoC
Next.js Acceso no autorizado CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 98
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.