Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC1
Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Apache Log4j2 RCE( CVE-2021-44228)验证环境
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
vulnerability POC
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC35
Vulnerability CVE-2021-44228 checker
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC155
Hashes for vulnerable LOG4J versions
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
CVE-2021-44228 server-side fix for minecraft servers.
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Mitigation for Log4Shell Security Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
log4shell sample application (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC195
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
CVE-2021-44228 DFIR Notes
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC950
🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1.851
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC106
Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
TheArqsz/CVE-2021-44228-PoC
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC19
Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2
CVE-2021-44228CRITICALsob ataqueransomware09 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC18
Exploit iDRAC 7 & 8 firmware < 2.52.52.52
CVE-2018-120709 dez 2021
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISCO
abrir
GitHub PoC2
CVE-2021-43798Exp多线程批量验证脚本
CVE-2021-43798HIGHsob ataque09 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC9
Grafana-POC任意文件读取漏洞(CVE-2021-43798)
CVE-2021-43798HIGHsob ataque09 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC5
Simple program for exploit grafana
CVE-2021-43798HIGHsob ataque09 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC89
Apache Log4j 远程代码执行
CVE-2021-44228CRITICALsob ataqueransomware09 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
PoC of FortiWAN auth bypass (https://www.fortiguard.com/psirt/FG-IR-21-048)
CVE-2021-26102CRITICAL09 dez 2021
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot
53RISCO
abrir
GitHub PoC1
CVE-2021-27928-POC
CVE-2021-2792809 dez 2021
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISCO
abrir
GitHub PoC
update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053
CVE-2019-905309 dez 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
RamPanic/CVE-2019-19609-EXPLOIT
CVE-2019-1960908 dez 2021
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir
GitHub PoC
Grafana File-Read Vuln
CVE-2021-43798HIGHsob ataque08 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC36
Proof of Concept Exploit for ManageEngine ServiceDesk Plus CVE-2021-44077
CVE-2021-44077CRITICALsob ataque08 dez 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISCO
abrir
GitHub PoC17
grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL
CVE-2021-43798HIGHsob ataque08 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC1
CVE-2021-43798-Grafana任意文件读取漏洞
CVE-2021-43798HIGHsob ataque08 dez 2021
Grafana path traversal
100RISCO
abrir
anteriorpágina 348 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.