Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.836exploits catalogados
35.811CVEs con explotación pública
24.695probados en laboratorio
77.836 exploits
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
roticagas/CVE-2021-44228-Demo
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
CVE-2021-44228CRITICALbajo ataqueransomwareremotejava14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
CVE-2021-44228CRITICALbajo ataqueransomwareremotejava14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2021-44228 Response Scripts
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
Check CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Demo project to evaluate Log4j2 Vulnerability | CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
CVE-2019-9581webappsphp14 dic 2021
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RIESGO
abrir
GitHub PoC395
A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Sample docker-compose setup to show how this exploit works
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Endpoint to test CVE-2021-44228 – Log4j 2
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Little recap of the log4j2 remote code execution (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC18
Log4j2 CVE-2021-44228 revshell, ofc it suck!!
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Details : CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC22
A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC439
Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
didoatanasov/cve-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution (RCE) by logging a certain string. Given how ubiquitous this library is, the impact of the exploit (full server control), and how easy it is to exploit, the impact of this vulnerability is quite severe. We're calling it "Log4Shell" for short.
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
flxhaas/Scan-CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Mass recognition tool for CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
Some tools to help mitigating Apache Log4j 2 CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
A singular file to protect as many Minecraft servers and clients as possible from the Log4j exploit (CVE-2021-44228).
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Professional Service scripts to aid in the identification of affected Java applications in TeamServer
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC6
Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/
CVE-2021-44228CRITICALbajo ataqueransomware13 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 625 / 2595siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.