Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC47
An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
An automated header extensive scanner for detecting log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC94
A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
VerveIndustrialProtection/CVE-2021-44228-Log4j
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
Dockerized honeypot for CVE-2021-44228.
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC72
Small example repo for looking into log4j CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
pravin-pp/log4j2-CVE-2021-45046
CVE-2021-45046CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC21
Log4j 2.15.0 Privilege Escalation -- CVE-2021-45046
CVE-2021-45046CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC9
Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
Oh no another one
CVE-2021-45046CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC
Replicating CVE-2021-45046
CVE-2021-45046CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC1
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.
CVE-2021-4504315 dic 2021
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RIESGO
abrir
GitHub PoC3
Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC18
Log4j2 CVE-2021-44228 revshell, ofc it suck!!
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
Check CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC9
Repo containing all info, scripts, etc. related to CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2019-17571CRITICAL14 dic 2021
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RIESGO
abrir
GitHub PoC350
Scanners for Jar files that may be vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
roticagas/CVE-2021-44228-Demo
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Sample docker-compose setup to show how this exploit works
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Details : CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Little recap of the log4j2 remote code execution (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Endpoint to test CVE-2021-44228 – Log4j 2
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC395
A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 339 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.