Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
13.937 exploits
GitHub PoC9
A lab demonstration of the log4shell vulnerability: CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Provide patched version of Log4J against CVE-2021-44228 and CVE-2021-45046 as well as a script to manually patch it yourself
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
A simple simulation of the infamous CVE-2021-44228 issue.
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
nu11secur1ty/CVE-2021-44228-VULN-APP
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
CVE-2021-43798 Grafana任意文件读取
CVE-2021-43798HIGHsob ataque17 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC5
Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
ConnectWise also known as ScreenConnect CVE-2019-16516
CVE-2019-1651617 dez 2021
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISCO
abrir
GitHub PoC9
This project will help to test the Log4j CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Test exploit of CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.
CVE-2021-45046CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Log4Shell CVE-2021-44228 Vulnerability Scanner and POC
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2021-44228-Apache-Log4j
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC14
Public testing data. Samples of log4j library versions to help log4j scanners / detectors improve their accuracy for detecting CVE-2021-45046 and CVE-2021-44228. TAG_TESTING, OWNER_KEN, DC_PUBLIC
CVE-2021-45046CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC2
Simple webapp that is vulnerable to Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Scanner recursivo de arquivos desenvolvido em Python 3 para localização e varredura de versões vulneráveis do Log4j2, contemplando análise interna de arquivos JAR (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 e CVE-2021-44832)
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Log4J checker for Apache CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the presence of JndiLookup.class.
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
log4j mitigation work
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
log4j vulnerability wrapper scanner for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
kannthu/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Vulnmachines/log4j-cve-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC12
Detect and fix log4j log4shell vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 339 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.