Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
77,813 exploits
GitHub PoC33
Scan and patch tool for CVE-2021-44228 and related log4j concerns.
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4j2 CVE-2021-44228 hack demo for a springboot app
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
POC for CVE-2021-44228 within Springboot
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Python script to detect Log4Shell Vulnerability CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
相关的复现和文档
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
halencarjunior/grafana-CVE-2021-43798
CVE-2021-43798HIGHunder attack21 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC
Webmin Local File Include (unauthenticated)
CVE-2006-339221 Dec 2021
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
GitHub PoC57
Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution - log4j (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware21 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-6693MEDIUMunder attackransomware21 Dec 2021
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
GitHub PoC7
Decrypt FortiGate configuration secrets
CVE-2019-6693MEDIUMunder attackransomware21 Dec 2021
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
Exploit-DB
WBCE CMS 1.5.1 - Admin Password Reset
CVE-2021-3817CRITICALwebappsphp20 Dec 2021
SQL Injection in wbce/wbce_cms
60RISK
open
GitHub PoC
intel-xeon/CVE-2021-44228---detection-with-PowerShell
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
offensity/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware20 Dec 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC2
Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC38
log4j2 RCE漏洞(CVE-2021-44228)内网扫描器,可用于在不出网的条件下进行漏洞扫描,帮助企业内部快速发现Log4jShell漏洞。
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
bumheehan/cve-2021-44228-log4j-test
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
log4j2 Log4Shell CVE-2021-44228 proof of concept
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
a project written in go and java i abandoned for CVE-2021-44228 try to fix it if you can XD
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC85
Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)
CVE-2021-45046CRITICALunder attackransomware20 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack20 Dec 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2018-3639MEDIUM20 Dec 2021
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware20 Dec 2021
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
Bash que instala los sploit CVE-2017-0781 y CVE-2017-0785 y lo necesario para su usos.
CVE-2017-078120 Dec 2021
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware19 Dec 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware19 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC105
Exploiting CVE-2021-44228 in vCenter for remote code execution and more.
CVE-2021-44228CRITICALunder attackransomware19 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware19 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 620 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.