Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
13.937 exploits
GitHub PoC2
Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
avirahul007/CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
A one-stop repo/ information hub for all log4j vulnerability-related information.
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC47
An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)
CVE-2021-44228CRITICALsob ataqueransomware15 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Little recap of the log4j2 remote code execution (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Grafana8.x 任意文件读取
CVE-2021-43798HIGHsob ataque14 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC
Endpoint to test CVE-2021-44228 – Log4j 2
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC395
A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
Check CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2021-44228 Response Scripts
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2019-17571CRITICAL14 dez 2021
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RISCO
abrir
GitHub PoC16
ab0x90/CVE-2021-44228_PoC
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC40
Tools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Simple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC22
A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC13
Log4j Shield - fast ⚡, scalable and easy to use Log4j vulnerability CVE-2021-44228 finder and patcher
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC350
Scanners for Jar files that may be vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC9
Repo containing all info, scripts, etc. related to CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution (RCE) by logging a certain string. Given how ubiquitous this library is, the impact of the exploit (full server control), and how easy it is to exploit, the impact of this vulnerability is quite severe. We're calling it "Log4Shell" for short.
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC18
Log4j2 CVE-2021-44228 revshell, ofc it suck!!
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 341 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.