Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC
相关的复现和文档
CVE-2021-44228CRITICALbajo ataqueransomware21 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC85
Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)
CVE-2021-45046CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC2
log4j2 Log4Shell CVE-2021-44228 proof of concept
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
bumheehan/cve-2021-44228-log4j-test
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC38
log4j2 RCE漏洞(CVE-2021-44228)内网扫描器,可用于在不出网的条件下进行漏洞扫描,帮助企业内部快速发现Log4jShell漏洞。
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
a project written in go and java i abandoned for CVE-2021-44228 try to fix it if you can XD
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
intel-xeon/CVE-2021-44228---detection-with-PowerShell
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware20 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
offensity/CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware20 dic 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
Bash que instala los sploit CVE-2017-0781 y CVE-2017-0785 y lo necesario para su usos.
CVE-2017-078120 dic 2021
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
GitHub PoC65
CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware19 dic 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC106
Exploiting CVE-2021-44228 in vCenter for remote code execution and more.
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
Vulnerability analysis, patch management and exploitation tool forCVE-2021-44228 / CVE-2021-45046 / CVE-2021-4104
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC8
A Proof of Concept of the Log4j vulnerabilities (CVE-2021-44228) over Java-RMI
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
Identifying all log4j components across on local windows servers. CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
Demo to show how Log4Shell / CVE-2021-44228 vulnerability works
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
kkyehit/log4j_CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware19 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
A scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it
CVE-2021-44228CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
can find, analyse and patch Log4J files because of CVE-2021-44228, CVE-2021-45046
CVE-2021-44228CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
An attempt to understand the log4j vulnerability by looking through the code
CVE-2021-44228CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
ludy-dev/cve-2021-45046
CVE-2021-45046CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC
Self-contained lab environment that runs the exploit safely, all from docker compose
CVE-2021-44228CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC194
shmilylty/cve-2021-22005-exp
CVE-2021-22005CRITICALbajo ataqueransomware18 dic 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) docker lab
CVE-2021-44228CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it works!
CVE-2021-44228CRITICALbajo ataqueransomware18 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 336 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.