Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
13.885 exploits
GitHub PoC
Mass recognition tool for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
flxhaas/Scan-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC37
OpenIOC rules to facilitate hunting for indicators of compromise
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC20
This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC291
PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Some files for red team/blue team investigations into CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
fail2ban filter that catches attacks againts log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
maxant/log4j2-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC276
Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)
CVE-2021-42278HIGHsob ataqueransomware13 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC19
Log4j Exploit Detection Logic for Zeek
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Log4Shell A test for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
Python3 script for scanning CVE-2021-44228 (Log4shell) vulnerable machines.
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
Public IOCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Compiling links of value i find regarding CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1.015
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHsob ataqueransomware13 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC6
Exploiting CVE-2021-42278 and CVE-2021-42287
CVE-2021-42278HIGHsob ataqueransomware13 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC6
This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
log4j2 CVE-2021-44228 POC
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC102
Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
simple python scanner to check if your network is vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2021-4428 复现
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Simple tool for scanning entire directories for attempts of CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
DiCanio/CVE-2021-44228-docker-example
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
CVE-2021-44228 (Log4Shell) Proof of Concept
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
pythonic pure python RCE exploit for CVE-2021-44228 log4shell
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC352
Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC27
Spring Boot Log4j - CVE-2021-44228 Docker Lab
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC52
Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 342 / 463próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.