Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
13.937 exploits
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC14
Public testing data. Samples of log4j library versions to help log4j scanners / detectors improve their accuracy for detecting CVE-2021-45046 and CVE-2021-44228. TAG_TESTING, OWNER_KEN, DC_PUBLIC
CVE-2021-45046CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC
CVE-2021-44228-Apache-Log4j
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
kannthu/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALsob ataqueransomware16 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
Fast filesystem scanner for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
pravin-pp/log4j2-CVE-2021-45046
CVE-2021-45046CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC
Replicating CVE-2021-45046
CVE-2021-45046CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC4
Oh no another one
CVE-2021-45046CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC21
Log4j 2.15.0 Privilege Escalation -- CVE-2021-45046
CVE-2021-45046CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC
This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC72
Small example repo for looking into log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
avirahul007/CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
Dockerized honeypot for CVE-2021-44228.
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC94
A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC9
Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
A one-stop repo/ information hub for all log4j vulnerability-related information.
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
An automated header extensive scanner for detecting log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
VerveIndustrialProtection/CVE-2021-44228-Log4j
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2021-44228 demo webapp
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
Scans for Log4j versions effected by CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Data we are receiving from our honeypots about CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 340 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.