Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC
0xcucumbersalad/cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC53
yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL25 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
CVE-2025-29972CRITICAL25 mar 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RISCO
abrir
GitHub PoC
somatrasss/CVE-2025-29306
CVE-2025-29306CRITICAL25 mar 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir
GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Check if a username is valid on the SSH server by attempting an authentication. The server response will indicate whether the username exists.
CVE-2018-15473MEDIUM25 mar 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
CVE-2024-31114CRITICAL25 mar 2025
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
CVE-2025-22912
CVE-2025-22912CRITICAL25 mar 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RISCO
abrir
GitHub PoC
0xPb1/Next.js-CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
jeymo092/cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC3
Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
CVE-2025-29927 Authorization Bypass in Next.js Middleware
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC3
CVE-2025-29927 Proof of Concept
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Next.Js 权限绕过漏洞(CVE-2025-29927)
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
Next.js Middleware Auth Bypass
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
Next.js 中间件授权绕过漏洞测试环境 (CVE-2025-29927)
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2002-0082
CVE-2002-008224 mar 2025
The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly
28RISCO
abrir
GitHub PoC91
CVE-2025-1974
CVE-2025-1974CRITICAL24 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC6
CVE-2025-29927 lab
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
ejaboz/cve-2024-24919
CVE-2024-24919HIGHsob ataqueransomware24 mar 2025
Information disclosure
100RISCO
abrir
GitHub PoC7
A playground to test the RCE exploit for tomcat CVE-2025-24813
CVE-2025-24813CRITICALsob ataque24 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
CVE-2024-51793CRITICAL24 mar 2025
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC5
Demo for Next.js middleware bypass - CVE-2025-29927
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
CVE-2025-29927の検証
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC4
Session Exploit
CVE-2025-24813CRITICALsob ataque24 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC2
CVE-2025-29927 Exploit Checker
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache Commons Text versions < 1.10.
CVE-2022-4288924 mar 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
Sigma Rule for CVE-2025–29927 Detection
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass
CVE-2025-29927CRITICAL24 mar 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
anteriorpágina 223 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.