Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
13,885 exploits
GitHub PoC47
An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
An automated header extensive scanner for detecting log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC94
A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
VerveIndustrialProtection/CVE-2021-44228-Log4j
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Dockerized honeypot for CVE-2021-44228.
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC72
Small example repo for looking into log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
pravin-pp/log4j2-CVE-2021-45046
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC21
Log4j 2.15.0 Privilege Escalation -- CVE-2021-45046
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC9
Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Oh no another one
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC
Replicating CVE-2021-45046
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC1
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.
CVE-2021-4504315 Dec 2021
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISK
open
GitHub PoC3
Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC18
Log4j2 CVE-2021-44228 revshell, ofc it suck!!
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Check CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
Repo containing all info, scripts, etc. related to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2019-17571CRITICAL14 Dec 2021
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RISK
open
GitHub PoC350
Scanners for Jar files that may be vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
roticagas/CVE-2021-44228-Demo
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Sample docker-compose setup to show how this exploit works
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Details : CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Little recap of the log4j2 remote code execution (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Endpoint to test CVE-2021-44228 – Log4j 2
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC395
A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 339 / 463next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.