Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
77.866 exploits
GitHub PoC1.015
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHsob ataqueransomware13 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC13
zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
helsecert/CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
:boom: Automox Windows Agent Privilege Escalation Exploit
CVE-2021-4332613 dez 2021
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISCO
abrir
GitHub PoC11
Scanner for Log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Some files for red team/blue team investigations into CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
fail2ban filter that catches attacks againts log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Compiling links of value i find regarding CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHsob ataqueransomware13 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC247
a fast check, if your server could be vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3.421
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
Python3 script for scanning CVE-2021-44228 (Log4shell) vulnerable machines.
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Log4J CVE-2021-44228 : Mitigation Cheat Sheet
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC20
This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
Public IOCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Demonstration of CVE-2021-44228 with a possible strategic fix.
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC37
OpenIOC rules to facilitate hunting for indicators of compromise
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHsob ataqueransomware13 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHsob ataqueransomware13 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC1
Using code search to help fix/mitigate log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
tica506/Siem-queries-for-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Exploit-DB
HD-Network Real-time Monitoring System 2.0 - Local File Inclusion (LFI)
CVE-2021-45043remotelinux13 dez 2021
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISCO
abrir
GitHub PoC2
Find log4j for CVE-2021-44228 on some places * Log4Shell
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC86
Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Metasploit300
WordPress Modern Events Calendar SQLi Scanner
CVE-2021-2494613 dez 2021
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
60RISCO
abrir
GitHub PoC291
PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC70
log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload
CVE-2021-44228CRITICALsob ataqueransomware13 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 628 / 2.596próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.