Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
13.885 exploits
GitHub PoC25
Hot-patch CVE-2021-44228 by exploiting the vulnerability itself.
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC178
An All-In-One Pure Python PoC for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC32
CVE-2021-44228,log4j2 burp插件 Java版本,dnslog选取了非dnslog.cn域名
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC44
RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
A bare minimum proof-of-concept for Log4j2 JNDI RCE vulnerability (CVE-2021-44228/Log4Shell).
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC640
A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too! TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Apache Log4j2 CVE-2021-44228 RCE Demo with RMI and LDAP
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC17
Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
log4j2漏洞复现
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC12
An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
uint0/cve-2021-44228-helpers
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
gixxyboy/CVE-2021-43798
CVE-2021-43798HIGHsob ataque12 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC72
A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC66
Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC52
Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC15
IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC9
CVE-2021-43936 is a critical vulnerability (CVSS3 10.0) leading to Remote Code Execution (RCE) in WebHMI Firmware.
CVE-2021-43936CRITICAL12 dez 2021
Distributed Data Systems WebHM
60RISCO
abrir
GitHub PoC352
Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
pravin-pp/log4j2-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
Log4j RCE - (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Sample log4j shell exploit
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC46
Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect in-depth (layered archives jar/zip/tar/war and scans for vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105). Binaries for Windows, Linux and OsX, but can be build on each platform supported by supported Golang.
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC27
Spring Boot Log4j - CVE-2021-44228 Docker Lab
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Panyaprach/Prove-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Poc of log4j2 (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
DiCanio/CVE-2021-44228-docker-example
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Dockerized Go app for testing the CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC49
Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC6
Python script that sends CVE-2021-44228 log4j payload requests to url list
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
Log4J CVE-2021-44228 Minecraft PoC
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 343 / 463próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.