Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC2
Log4jshell - CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware07 ene 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
alexpena5635/CVE-2021-44228_scanner-main-Modified-
CVE-2021-44228CRITICALbajo ataqueransomware05 ene 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Bassmaster Plugin NodeJS RCE
CVE-2014-720504 ene 2022
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RIESGO
abrir
GitHub PoC
Atmail XSS-CSRF-RCE Exploit Chain
CVE-2012-259304 ene 2022
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta
23RIESGO
abrir
GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
CVE-2017-0147HIGHbajo ataqueransomware04 ene 2022
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC9
darkpills/CVE-2021-25094-tatsu-preauth-rce
CVE-2021-2509403 ene 2022
Tatsu < 3.3.12 - Unauthenticated RCE
60RIESGO
abrir
GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
CVE-2012-0158HIGHbajo ataque03 ene 2022
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RIESGO
abrir
GitHub PoC
Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware03 ene 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.
CVE-2021-44228CRITICALbajo ataqueransomware31 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Presents how to exploit CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware30 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
trganda/CVE-2021-22204
CVE-2021-22204MEDIUMbajo ataque29 dic 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC4
Auerswald VoIP System Secret Backdoors -PoC
CVE-2021-4085929 dic 2021
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RIESGO
abrir
GitHub PoC
d4rk30/CVE-2017-12943
CVE-2017-1294329 dic 2021
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE
35RIESGO
abrir
GitHub PoC2
Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit
CVE-2021-40444HIGHbajo ataqueransomware28 dic 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC11
CVE-2019-9053 Exploit for Python 3
CVE-2019-905328 dic 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.
CVE-2021-44228CRITICALbajo ataqueransomware28 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
"Lavel Exploit CVE-2018-15133 is a powerful exploit that allows attackers to gain unauthorized access to vulnerable systems. This exploit was originally developed as part of a Capture The Flag (CTF) challenge and has since been used by security researchers and ethical hackers to identify and address vulnerabilities in web applications.
CVE-2018-15133HIGHbajo ataque28 dic 2021
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC209
A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager
CVE-2021-44228CRITICALbajo ataqueransomware28 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
Auerswald COMpact 8.0B Backdoors exploit
CVE-2021-4085928 dic 2021
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RIESGO
abrir
GitHub PoC
Quick and dirty scanner, hitting common ports looking for Log4Shell (CVE-2021-44228) vulnerability
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
IOCs for CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Regra ModSec para proteção log4j2 - CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Detection script for CVE-2021-42278 and CVE-2021-42287
CVE-2021-42278HIGHbajo ataqueransomware27 dic 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC
Log4Shell (Cve-2021-44228) Proof Of Concept
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j
CVE-2021-44228CRITICALbajo ataqueransomware27 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
this repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research
CVE-2021-44228CRITICALbajo ataqueransomware25 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
This is a basic ROP based exploit for CVE 2020-14871. CVE 2020-14871 is a vulnerability in Sun Solaris systems libpam library, and exploitable over ssh
CVE-2020-14871CRITICALbajo ataque25 dic 2021
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
anteriorpágina 334 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.