Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
13,885 exploits
GitHub PoC
this repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research
CVE-2021-44228CRITICALunder attackransomware25 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228 检查工具
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC170
Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC8
A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)
CVE-2019-834124 Dec 2021
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where
35RISK
open
GitHub PoC
Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
PoC for CVE-2021-44228.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
general purpose workaround for the log4j CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Log4Shell(CVE-2021-45046) Sandbox Signature
CVE-2021-45046CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC7
open detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware23 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC10
Apache 远程代码执行 (CVE-2021-42013)批量检测工具:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点,发现 Apache HTTP Server 2.4.50 中针对 CVE-2021-41773 的修复不够充分。攻击者可以使用路径遍历攻击将 URL 映射到由类似别名的指令配置的目录之外的文件。如果这些目录之外的文件不受通常的默认配置“要求全部拒绝”的保护,则这些请求可能会成功。如果还为这些别名路径启用了 CGI 脚本,则这可能允许远程代码执行。此问题仅影响 Apache 2.4.49 和 Apache 2.4.50,而不影响更早版本。
CVE-2021-42013CRITICALunder attackransomware23 Dec 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC24
一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.
CVE-2016-4437CRITICALunder attack23 Dec 2021
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
GitHub PoC1
Scan and patch tool for CVE-2021-44228 and related log4j concerns.
CVE-2021-44228CRITICALunder attackransomware23 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Ansible playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 for Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware23 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
CVE-2021-22205 的批量检测脚本
CVE-2021-22205CRITICALunder attackransomware22 Dec 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC2
Log4Shell Demo with AWS
CVE-2021-44228CRITICALunder attackransomware22 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.
CVE-2021-44228CRITICALunder attackransomware22 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC14
A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner
CVE-2021-44228CRITICALunder attackransomware22 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS
CVE-2021-44228CRITICALunder attackransomware22 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware22 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
Generic Scanner for Apache log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware22 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
halencarjunior/grafana-CVE-2021-43798
CVE-2021-43798HIGHunder attack21 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC57
Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution - log4j (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Python script to detect Log4Shell Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4j2 CVE-2021-44228 hack demo for a springboot app
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
相关的复现和文档
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Webmin Local File Include (unauthenticated)
CVE-2006-339221 Dec 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
GitHub PoC33
Scan and patch tool for CVE-2021-44228 and related log4j concerns.
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
POC for CVE-2021-44228 within Springboot
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 335 / 463next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.