Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
13.937 exploits
GitHub PoC1404
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
CVE-2021-42287HIGHbajo ataqueransomware11 dic 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC1
chilliwebs/CVE-2021-44228_Example
CVE-2021-44228CRITICALbajo ataqueransomware11 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC46
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798HIGHbajo ataque11 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC1
CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application.
CVE-2021-43798HIGHbajo ataque11 dic 2021
Grafana path traversal
100RIESGO
abrir
GitHub PoC4
CVE-2017-12617 is a critical vulnerability leading to Remote Code Execution (RCE) in Apache Tomcat.
CVE-2017-12617HIGHbajo ataque10 dic 2021
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC
varppi/CVE-2012-2982
CVE-2012-298210 dic 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC1851
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC106
Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
TheArqsz/CVE-2021-44228-PoC
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC469
Remote Code Injection In Log4j
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC182
Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC126
一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
CVE-2021-44228 server-side fix for minecraft servers.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC950
🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
racoon-rac/CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC6
CVE-2021-44228 fix
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC49
A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer)
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC4
Vulnerable to CVE-2021-44228. trustURLCodebase is not required.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC155
Hashes for vulnerable LOG4J versions
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC126
A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1139
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC35
Vulnerability CVE-2021-44228 checker
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
vulnerability POC
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC3
A small server for verifing if a given java program is succeptibel to CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
Apache Log4j2 RCE( CVE-2021-44228)验证环境
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC7
CVE-2021-44228 DFIR Notes
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC5
A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").
CVE-2021-44228CRITICALbajo ataqueransomware10 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 347 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.