Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
77.866 exploits
GitHub PoC1
An awesome curated list of repos for CVE-2021-44228. ``Apache Log4j 2``
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
A micro lab for CVE-2021-44228 (log4j)
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC15
IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Known IoCs for log4j framework vulnerability
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC52
Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Panyaprach/Prove-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Sample log4j shell exploit
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC46
Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect in-depth (layered archives jar/zip/tar/war and scans for vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105). Binaries for Windows, Linux and OsX, but can be build on each platform supported by supported Golang.
CVE-2021-44228CRITICALsob ataqueransomware12 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-43936CRITICAL12 dez 2021
Distributed Data Systems WebHM
60RISCO
abrir
GitHub PoC1
CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application.
CVE-2021-43798HIGHsob ataque11 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC46
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798HIGHsob ataque11 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC
Apache Log4j CVE-2021-44228 漏洞复现
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
vorburger/Log4j_CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC842
CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC23
A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
byteboycn/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC9
Public IoCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC16
Log4Shell CVE-2021-44228 mitigation tester
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHsob ataqueransomware11 dez 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque11 dez 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC4
M1ngGod/CVE-2021-44228-Log4j-lookup-Rce
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Небольшой мод направленный на устранение уязвимости CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC860
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Simple demo of CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
s4msec/CVE-2007-2447
CVE-2007-244711 dez 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
anteriorpágina 631 / 2.596próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.