Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC100
Collection of materials relating to FORCEDENTRY
CVE-2021-30860HIGHbajo ataque25 dic 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RIESGO
abrir
GitHub PoC7
PoC for CVE-2021-44228.
CVE-2021-44228CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.
CVE-2021-44228CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)
CVE-2019-834124 dic 2021
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where
35RIESGO
abrir
GitHub PoC
CVE-2021-44228 检查工具
CVE-2021-44228CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
general purpose workaround for the log4j CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Log4Shell(CVE-2021-45046) Sandbox Signature
CVE-2021-45046CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC8
A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC170
Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.
CVE-2021-44228CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat
CVE-2021-44228CRITICALbajo ataqueransomware24 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
Ansible playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 for Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALbajo ataqueransomware23 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
open detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALbajo ataqueransomware23 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Scan and patch tool for CVE-2021-44228 and related log4j concerns.
CVE-2021-44228CRITICALbajo ataqueransomware23 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC24
一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.
CVE-2016-4437CRITICALbajo ataque23 dic 2021
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
GitHub PoC10
Apache 远程代码执行 (CVE-2021-42013)批量检测工具:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点,发现 Apache HTTP Server 2.4.50 中针对 CVE-2021-41773 的修复不够充分。攻击者可以使用路径遍历攻击将 URL 映射到由类似别名的指令配置的目录之外的文件。如果这些目录之外的文件不受通常的默认配置“要求全部拒绝”的保护,则这些请求可能会成功。如果还为这些别名路径启用了 CGI 脚本,则这可能允许远程代码执行。此问题仅影响 Apache 2.4.49 和 Apache 2.4.50,而不影响更早版本。
CVE-2021-42013CRITICALbajo ataqueransomware23 dic 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.
CVE-2021-44228CRITICALbajo ataqueransomware22 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware22 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Log4Shell Demo with AWS
CVE-2021-44228CRITICALbajo ataqueransomware22 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC14
A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner
CVE-2021-44228CRITICALbajo ataqueransomware22 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
Generic Scanner for Apache log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware22 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Log4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS
CVE-2021-44228CRITICALbajo ataqueransomware22 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
CVE-2021-22205 的批量检测脚本
CVE-2021-22205CRITICALbajo ataqueransomware22 dic 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC33
Scan and patch tool for CVE-2021-44228 and related log4j concerns.
CVE-2021-44228CRITICALbajo ataqueransomware21 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Python script to detect Log4Shell Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware21 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
相关的复现和文档
CVE-2021-44228CRITICALbajo ataqueransomware21 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC57
Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution - log4j (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware21 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
Decrypt FortiGate configuration secrets
CVE-2019-6693MEDIUMbajo ataqueransomware21 dic 2021
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir
GitHub PoC
halencarjunior/grafana-CVE-2021-43798
CVE-2021-43798HIGHbajo ataque21 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Webmin Local File Include (unauthenticated)
CVE-2006-339221 dic 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
GitHub PoC1
POC for CVE-2021-44228 within Springboot
CVE-2021-44228CRITICALbajo ataqueransomware21 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 335 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.