Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9.029Nuclei 4.416Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.392 exploits
GitHub PoC★ 53
yoshino-s/CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
Azure Storage Resource Provider Spoofing Vulnerability
48RISCO
abrir ↗GitHub PoC
somatrasss/CVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir ↗GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Check if a username is valid on the SSH server by attempting an authentication. The server response will indicate whether the username exists.
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗GitHub PoC
CVE-2025-22912
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RISCO
abrir ↗GitHub PoC★ 3
Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-29927 Authorization Bypass in Next.js Middleware
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 3
CVE-2025-29927 Proof of Concept
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 2
Next.js 中间件授权绕过漏洞测试环境 (CVE-2025-29927)
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
CVE-2002-0082
The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly
28RISCO
abrir ↗GitHub PoC★ 7
A playground to test the RCE exploit for tomcat CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 1
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗GitHub PoC★ 5
Demo for Next.js middleware bypass - CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 4
Session Exploit
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache Commons Text versions < 1.10.
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC
Sigma Rule for CVE-2025–29927 Detection
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.