Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC3
A small server for verifing if a given java program is succeptibel to CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1139
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
log4shell sample application (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Mitigation for Log4Shell Security Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
wheezysec/CVE-2021-44228-kusto
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
Vulnerable to CVE-2021-44228. trustURLCodebase is not required.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
CVE-2021-44228 server-side fix for minecraft servers.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
TheArqsz/CVE-2021-44228-PoC
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Apache Log4j2 RCE( CVE-2021-44228)验证环境
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
vulnerability POC
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC35
Vulnerability CVE-2021-44228 checker
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC155
Hashes for vulnerable LOG4J versions
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC19
Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC89
Apache Log4j 远程代码执行
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC8
PoC of FortiWAN auth bypass (https://www.fortiguard.com/psirt/FG-IR-21-048)
CVE-2021-26102CRITICAL09 dic 2021
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot
53RIESGO
abrir
GitHub PoC18
Exploit iDRAC 7 & 8 firmware < 2.52.52.52
CVE-2018-120709 dic 2021
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir
GitHub PoC5
Simple program for exploit grafana
CVE-2021-43798HIGHbajo ataque09 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC2
CVE-2021-43798Exp多线程批量验证脚本
CVE-2021-43798HIGHbajo ataque09 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC1
CVE-2021-27928-POC
CVE-2021-2792809 dic 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RIESGO
abrir
GitHub PoC
update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053
CVE-2019-905309 dic 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC9
Grafana-POC任意文件读取漏洞(CVE-2021-43798)
CVE-2021-43798HIGHbajo ataque09 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Grafana File-Read Vuln
CVE-2021-43798HIGHbajo ataque08 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC4
s1gh/CVE-2021-43798
CVE-2021-43798HIGHbajo ataque08 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC1
CVE-2021-43798-Grafana任意文件读取漏洞
CVE-2021-43798HIGHbajo ataque08 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC17
grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL
CVE-2021-43798HIGHbajo ataque08 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC
RamPanic/CVE-2019-19609-EXPLOIT
CVE-2019-1960908 dic 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
GitHub PoC36
Proof of Concept Exploit for ManageEngine ServiceDesk Plus CVE-2021-44077
CVE-2021-44077CRITICALbajo ataque08 dic 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RIESGO
abrir
GitHub PoC12
Grafanav8.*版本任意文件读取漏洞批量检测工具:该漏洞目前为0day漏洞,未授权的攻击者利用该漏洞,能够获取服务器敏感文件。
CVE-2021-43798HIGHbajo ataque07 dic 2021
Grafana path traversal
100RIESGO
abrir
anteriorpágina 346 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.