Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,402cataloged exploits
34,906CVEs with public exploitation
24,695lab-tested
13,907 exploits
GitHub PoC1
CVE-2021-44228 POC - Spring / Hibernate
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC45
Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class paths inside files
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Fixes CVE-2021-44228 in log4j by patching JndiLookup class
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
M1ngGod/CVE-2021-44228-Log4j-lookup-Rce
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Mitigation for Log4Shell Security Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1,139
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Apache Log4j2 RCE( CVE-2021-44228)验证环境
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
vulnerability POC
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC35
Vulnerability CVE-2021-44228 checker
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
A small server for verifing if a given java program is succeptibel to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC155
Hashes for vulnerable LOG4J versions
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
CVE-2021-44228 server-side fix for minecraft servers.
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC108
Deploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
wheezysec/CVE-2021-44228-kusto
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
CVE-2021-44228 fix
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC49
A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer)
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
log4shell sample application (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC195
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
CVE-2021-44228 DFIR Notes
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC950
🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC126
A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1,851
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC106
Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Vulnerable to CVE-2021-44228. trustURLCodebase is not required.
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
TheArqsz/CVE-2021-44228-PoC
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
varppi/CVE-2012-2982
CVE-2012-298210 Dec 2021
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
previouspage 346 / 464next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.