Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
77.813 exploits
GitHub PoC14
we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in their AWS account. The script enables security teams to identify external-facing AWS assets by running the exploit on them, and thus be able to map them and quickly patch them
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
A one-stop repo/ information hub for all log4j vulnerability-related information.
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
avirahul007/CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC21
Log4j 2.15.0 Privilege Escalation -- CVE-2021-45046
CVE-2021-45046CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC72
Small example repo for looking into log4j CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware15 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
i6c/MASS_CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware15 dic 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC2
Grafana8.x 任意文件读取
CVE-2021-43798HIGHbajo ataque14 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC40
Tools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
CVE-2019-9581webappsphp14 dic 2021
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RIESGO
abrir
Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
CVE-2021-44228CRITICALbajo ataqueransomwareremotejava14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
CVE-2021-44228CRITICALbajo ataqueransomwareremotejava14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2022-23305CRITICAL14 dic 2021
SQL injection in JDBC Appender in Apache Log4j V1
60RIESGO
abrir
GitHub PoC16
ab0x90/CVE-2021-44228_PoC
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
roticagas/CVE-2021-44228-Demo
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Simple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC94
Tools for investigating Log4j CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Sample docker-compose setup to show how this exploit works
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC149
Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Demo project to evaluate Log4j2 Vulnerability | CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
municipalparkingservices/CVE-2021-44228-Scanner
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC10
Repo containing all info, scripts, etc. related to CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 624 / 2594siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.