Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.836exploits catalogados
35.811CVEs com exploração pública
24.695testados em laboratório
77.813 exploits
GitHub PoC4
Vulnerability analysis, patch management and exploitation tool forCVE-2021-44228 / CVE-2021-45046 / CVE-2021-4104
CVE-2021-44228CRITICALsob ataqueransomware19 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALsob ataqueransomware19 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
kkyehit/log4j_CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware19 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-40444HIGHsob ataqueransomware19 dez 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC105
Exploiting CVE-2021-44228 in vCenter for remote code execution and more.
CVE-2021-44228CRITICALsob ataqueransomware19 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware19 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
Demo to show how Log4Shell / CVE-2021-44228 vulnerability works
CVE-2021-44228CRITICALsob ataqueransomware19 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
Identifying all log4j components across on local windows servers. CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware19 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC194
shmilylty/cve-2021-22005-exp
CVE-2021-22005CRITICALsob ataqueransomware18 dez 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC
can find, analyse and patch Log4J files because of CVE-2021-44228, CVE-2021-45046
CVE-2021-44228CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
A scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it
CVE-2021-44228CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
An attempt to understand the log4j vulnerability by looking through the code
CVE-2021-44228CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Self-contained lab environment that runs the exploit safely, all from docker compose
CVE-2021-44228CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it works!
CVE-2021-44228CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-45046CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC1
ludy-dev/cve-2021-45046
CVE-2021-45046CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC1
A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) docker lab
CVE-2021-44228CRITICALsob ataqueransomware18 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALsob ataqueransomware18 dez 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC
Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque17 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Script - Workaround instructions to address CVE-2021-44228 in vCenter Server
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
PoC RCE Log4j CVE-2021-4428 para pruebas
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC9
This project will help to test the Log4j CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
nginx 1.15.10 patch against cve-2021-23017 (ingress version)
CVE-2021-2301717 dez 2021
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir
GitHub PoC
A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.
CVE-2021-45046CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir
GitHub PoC1
CVE-2021-43798 Grafana任意文件读取
CVE-2021-43798HIGHsob ataque17 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC
ConnectWise also known as ScreenConnect CVE-2019-16516
CVE-2019-1651617 dez 2021
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISCO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware17 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 621 / 2.594próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.