Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
13,885 exploits
GitHub PoC25
Hot-patch CVE-2021-44228 by exploiting the vulnerability itself.
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC72
A Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x "JNDI LDAP" vulnerability.
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
CVE-2021-43936 is a critical vulnerability (CVSS3 10.0) leading to Remote Code Execution (RCE) in WebHMI Firmware.
CVE-2021-43936CRITICAL12 Dec 2021
Distributed Data Systems WebHM
60RISK
open
GitHub PoC12
An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
A micro lab for CVE-2021-44228 (log4j)
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
DiCanio/CVE-2021-44228-docker-example
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
qingtengyun/cve-2021-44228-qingteng-patch
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
Log4J CVE-2021-44228 Minecraft PoC
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
b-abderrahmane/CVE-2021-44228-playground
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Небольшой мод направленный на устранение уязвимости CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4j-RCE (CVE-2021-44228) Proof of Concept
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
List of company advisories log4j
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Apache Log4j CVE-2021-44228 漏洞复现
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Simple demo of CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Test the CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
Public IoCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Content to help the community responding to the Log4j Vulnerability Log4Shell CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Test CVE-2018-15473 exploit on Shodan IP
CVE-2018-15473MEDIUM11 Dec 2021
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC5
A short demo of CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC46
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798HIGHunder attack11 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC1
CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application.
CVE-2021-43798HIGHunder attack11 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC35
Detections for CVE-2021-44228 inside of nested binaries
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
chilliwebs/CVE-2021-44228_Example
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Log4j2 CVE-2021-44228 复现和回显利用
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC45
Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class paths inside files
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1,058
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHunder attackransomware11 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC6
This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 344 / 463next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.