Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
13.885 exploits
GitHub PoC100
Collection of materials relating to FORCEDENTRY
CVE-2021-30860HIGHsob ataque25 dez 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISCO
abrir
GitHub PoC7
PoC for CVE-2021-44228.
CVE-2021-44228CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.
CVE-2021-44228CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)
CVE-2019-834124 dez 2021
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where
35RISCO
abrir
GitHub PoC
CVE-2021-44228 检查工具
CVE-2021-44228CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
general purpose workaround for the log4j CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Log4Shell(CVE-2021-45046) Sandbox Signature
CVE-2021-45046CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC8
A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC170
Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.
CVE-2021-44228CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat
CVE-2021-44228CRITICALsob ataqueransomware24 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
Ansible playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 for Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware23 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
open detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALsob ataqueransomware23 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Scan and patch tool for CVE-2021-44228 and related log4j concerns.
CVE-2021-44228CRITICALsob ataqueransomware23 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC24
一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.
CVE-2016-4437CRITICALsob ataque23 dez 2021
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISCO
abrir
GitHub PoC10
Apache 远程代码执行 (CVE-2021-42013)批量检测工具:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点,发现 Apache HTTP Server 2.4.50 中针对 CVE-2021-41773 的修复不够充分。攻击者可以使用路径遍历攻击将 URL 映射到由类似别名的指令配置的目录之外的文件。如果这些目录之外的文件不受通常的默认配置“要求全部拒绝”的保护,则这些请求可能会成功。如果还为这些别名路径启用了 CGI 脚本,则这可能允许远程代码执行。此问题仅影响 Apache 2.4.49 和 Apache 2.4.50,而不影响更早版本。
CVE-2021-42013CRITICALsob ataqueransomware23 dez 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.
CVE-2021-44228CRITICALsob ataqueransomware22 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware22 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Log4Shell Demo with AWS
CVE-2021-44228CRITICALsob ataqueransomware22 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC14
A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner
CVE-2021-44228CRITICALsob ataqueransomware22 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
Generic Scanner for Apache log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware22 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Log4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS
CVE-2021-44228CRITICALsob ataqueransomware22 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
CVE-2021-22205 的批量检测脚本
CVE-2021-22205CRITICALsob ataqueransomware22 dez 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC33
Scan and patch tool for CVE-2021-44228 and related log4j concerns.
CVE-2021-44228CRITICALsob ataqueransomware21 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Python script to detect Log4Shell Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware21 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
相关的复现和文档
CVE-2021-44228CRITICALsob ataqueransomware21 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC57
Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution - log4j (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware21 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
Decrypt FortiGate configuration secrets
CVE-2019-6693MEDIUMsob ataqueransomware21 dez 2021
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISCO
abrir
GitHub PoC
halencarjunior/grafana-CVE-2021-43798
CVE-2021-43798HIGHsob ataque21 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC
Webmin Local File Include (unauthenticated)
CVE-2006-339221 dez 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
GitHub PoC1
POC for CVE-2021-44228 within Springboot
CVE-2021-44228CRITICALsob ataqueransomware21 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 335 / 463próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.