Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
81.524 exploits
GitHub PoC
Next.js and the corrupt middleware...TRY TO HACK IT..!
CVE-2025-29927CRITICAL02 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
Exploit-DB
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
CVE-2024-6298CRITICALwebappsmultiple02 abr 2025
remote code execution
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM02 abr 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir ↗
GitHub PoC
corsisechero/CVE-2019-9193byVulHub
CVE-2019-9193—02 abr 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗
GitHub PoC
User Registration & Membership <= 4.1.2 - Authentication Bypass
CVE-2025-2594HIGH02 abr 2025
User Registration & Membership < 4.1.3 - Authentication Bypass
41RISCO
abrir ↗
GitHub PoC
DeividasTerechovas/SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation
CVE-2023-29357CRITICALsob ataqueransomware01 abr 2025
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 6
Vite 任意文件读取漏洞POC
CVE-2025-31125MEDIUMsob ataque01 abr 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMsob ataque01 abr 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗
GitHub PoC
Next.js CVE-2025-29927 güvenlik açığı hakkında
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC
JOOJIII/CVE-2025-29927
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4220HIGH01 abr 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC
congdong007/CVE-2024-50623-poc
CVE-2024-50623CRITICALsob ataqueransomware01 abr 2025
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISCO
abrir ↗
GitHub PoC★ 1
Next.js Middleware Bypass Vulnerability
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-50623CRITICALsob ataqueransomware01 abr 2025
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-22536CRITICALsob ataque01 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir ↗
GitHub PoC★ 4
SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass ACLs by desynchronizing request parsing between ICM and backend services using crafted Content-Length-based payloads.
CVE-2022-22536CRITICALsob ataque01 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir ↗
GitHub PoC
Authorization Bypass in Next.js Middleware
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC
Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.
CVE-2019-9053—31 mar 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-1974CRITICAL31 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗
GitHub PoC★ 7
针对CVE-2025-30208和CVE-2025-31125的漏洞利用
CVE-2025-30208MEDIUM31 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
GitHub PoC
B1gN0Se/Tomcat-CVE-2025-24813
CVE-2025-24813CRITICALsob ataque31 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC
CVE-2025-1974 PoC 코드
CVE-2025-1974CRITICAL31 mar 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗
GitHub PoC★ 5
Documentation and PoC for CVE-2023-21554 MSMQ Vulnerability
CVE-2023-21554CRITICAL31 mar 2025
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir ↗
GitHub PoC
Script to make changes on registry to fix CVE-2013-3900. It comes with an option to undo in case it breaks something on your environment.
CVE-2013-3900MEDIUMsob ataque31 mar 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗
GitHub PoC
backdoor.mirai.helloworld cve2018-20561, cve-2018-10562 해킹
CVE-2018-10562CRITICALsob ataqueransomware31 mar 2025
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque31 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC
mrrivaldo/CVE-2025-2294
CVE-2025-2294CRITICAL31 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗
GitHub PoC★ 13
Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.
CVE-2024-25600CRITICAL31 mar 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL31 mar 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
← anteriorpágina 360 / 2.718próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.