Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
13.937 exploits
GitHub PoC7
CVE-2021-36260
CVE-2021-36260CRITICALsob ataque13 dez 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC
demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC70
log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Find log4j for CVE-2021-44228 on some places * Log4Shell
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC20
This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Professional Service scripts to aid in the identification of affected Java applications in TeamServer
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Some files for red team/blue team investigations into CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC11
Scanner for Log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
fail2ban filter that catches attacks againts log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
maxant/log4j2-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Just a personal proof of concept of CVE-2021-44228 on log4j2
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC86
Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC37
OpenIOC rules to facilitate hunting for indicators of compromise
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Amaranese/CVE-2021-34527
CVE-2021-34527HIGHsob ataqueransomware13 dez 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC5
Log4J CVE-2021-44228 Minecraft PoC
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
An awesome curated list of repos for CVE-2021-44228. ``Apache Log4j 2``
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
Log4J (CVE-2021-44228) Exploit with Remote Command Execution (RCE)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC72
A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
Log4j RCE - (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Panyaprach/Prove-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
Check list of URLs against Log4j vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC27
Spring Boot Log4j - CVE-2021-44228 Docker Lab
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC12
An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
A micro lab for CVE-2021-44228 (log4j)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC52
Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Known IoCs for log4j framework vulnerability
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC44
RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC178
An All-In-One Pure Python PoC for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 344 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.