Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
77.866 exploits
GitHub PoC9
Public IoCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC46
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798HIGHsob ataque11 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC4
M1ngGod/CVE-2021-44228-Log4j-lookup-Rce
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
vorburger/Log4j_CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHsob ataqueransomware11 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC4
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
byteboycn/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC842
CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque11 dez 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application.
CVE-2021-43798HIGHsob ataque11 dez 2021
Grafana path traversal
100RISCO
abrir
GitHub PoC
Apache Log4j CVE-2021-44228 漏洞复现
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1.404
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
CVE-2021-42287HIGHsob ataqueransomware11 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
Небольшой мод направленный на устранение уязвимости CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
s4msec/CVE-2007-2447
CVE-2007-244711 dez 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC6
This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1.058
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHsob ataqueransomware11 dez 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHsob ataqueransomware11 dez 2021
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Test CVE-2018-15473 exploit on Shodan IP
CVE-2018-15473MEDIUM11 dez 2021
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
wheezysec/CVE-2021-44228-kusto
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Mitigation for Log4Shell Security Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
log4shell sample application (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC195
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALsob ataqueransomware10 dez 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 632 / 2.596próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.