Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC5
Log4J CVE-2021-44228 Minecraft PoC
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
pravin-pp/log4j2-CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC352
Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
pythonic pure python RCE exploit for CVE-2021-44228 log4shell
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC8
CVE-2021-44228 (Log4Shell) Proof of Concept
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC9
CVE-2021-43936 is a critical vulnerability (CVSS3 10.0) leading to Remote Code Execution (RCE) in WebHMI Firmware.
CVE-2021-43936CRITICAL12 dic 2021
Distributed Data Systems WebHM
60RIESGO
abrir
GitHub PoC640
A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
A bare minimum proof-of-concept for Log4j2 JNDI RCE vulnerability (CVE-2021-44228/Log4Shell).
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
b-abderrahmane/CVE-2021-44228-playground
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Content to help the community responding to the Log4j Vulnerability Log4Shell CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Log4j-RCE (CVE-2021-44228) Proof of Concept
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Test the CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
List of company advisories log4j
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC16
Log4Shell CVE-2021-44228 mitigation tester
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Apache Log4j CVE-2021-44228 漏洞复现
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Небольшой мод направленный на устранение уязвимости CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC23
A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC861
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC6
This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Simple demo of CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
vorburger/Log4j_CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC9
Public IoCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1058
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHbajo ataqueransomware11 dic 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC1
s4msec/CVE-2007-2447
CVE-2007-244711 dic 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC1
chilliwebs/CVE-2021-44228_Example
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC35
Detections for CVE-2021-44228 inside of nested binaries
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC46
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798HIGHbajo ataque11 dic 2021
Grafana path traversal
100RIESGO
abrir
anteriorpágina 344 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.