Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.944 exploits
GitHub PoC1.404
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
CVE-2021-42287HIGHsob ataqueransomware11 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC16
Log4Shell CVE-2021-44228 mitigation tester
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC23
A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC861
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
vorburger/Log4j_CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC46
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798HIGHsob ataque11 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC1
CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application.
CVE-2021-43798HIGHsob ataque11 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC2
docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC6
This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Test CVE-2018-15473 exploit on Shodan IP
CVE-2018-15473MEDIUM11 dez 2021
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
s4msec/CVE-2007-2447
CVE-2007-244711 dez 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC4
CVE-2017-12617 is a critical vulnerability leading to Remote Code Execution (RCE) in Apache Tomcat.
CVE-2017-12617HIGHsob ataque10 dez 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
GitHub PoC
varppi/CVE-2012-2982
CVE-2012-298210 dez 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
racoon-rac/CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC182
Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
vulnerability POC
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC35
Vulnerability CVE-2021-44228 checker
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC155
Hashes for vulnerable LOG4J versions
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC6
CVE-2021-44228 fix
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC49
A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer)
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC108
Deploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
A small server for verifing if a given java program is succeptibel to CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1.139
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC126
A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
log4shell sample application (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC195
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
CVE-2021-44228 DFIR Notes
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC469
Remote Code Injection In Log4j
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 347 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.