Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
13,885 exploits
GitHub PoC
CVE-2021-44228-Apache-Log4j
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Log4Shell Proof of Concept (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Log4Shell CVE-2021-44228 Vulnerability Scanner and POC
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4J checker for Apache CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
kannthu/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Vulnmachines/log4j-cve-2021-44228
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC10
This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC12
Detect and fix log4j log4shell vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
CVE-2021-44228 vulnerability in Apache Log4j library | Log4j vulnerability scanner on Windows machines.
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
log4shell (CVE-2021-44228) scanning tool
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
fasanhlieu/CVE-2021-2394
CVE-2021-2394CRITICAL15 Dec 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISK
open
GitHub PoC1
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.
CVE-2021-4504315 Dec 2021
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISK
open
GitHub PoC
CVE-2021-44228 demo webapp
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
An automated header extensive scanner for detecting log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
CrackerCat/CVE-2021-44228-Log4j-Payloads
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
VerveIndustrialProtection/CVE-2021-44228-Log4j
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Data we are receiving from our honeypots about CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
avirahul007/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC47
An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
A scanner and a proof of sample exploit for log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
A one-stop repo/ information hub for all log4j vulnerability-related information.
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 338 / 463next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.