Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
77,866 exploits
GitHub PoC94
A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
avirahul007/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Replicating CVE-2021-45046
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC14
we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in their AWS account. The script enables security teams to identify external-facing AWS assets by running the exploit on them, and thus be able to map them and quickly patch them
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC21
Log4j 2.15.0 Privilege Escalation -- CVE-2021-45046
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC4
Oh no another one
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC
A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
pravin-pp/log4j2-CVE-2021-45046
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC7
Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
i6c/MASS_CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware15 Dec 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC18
Log4j2 CVE-2021-44228 revshell, ofc it suck!!
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
CVE-2021-44228CRITICALunder attackransomwareremotejava14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Grafana8.x 任意文件读取
CVE-2021-43798HIGHunder attack14 Dec 2021
Grafana path traversal
100RISK
open
Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
CVE-2021-44228CRITICALunder attackransomwareremotejava14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
Log4j Shield - fast ⚡, scalable and easy to use Log4j vulnerability CVE-2021-44228 finder and patcher
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
municipalparkingservices/CVE-2021-44228-Scanner
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2022-23305CRITICAL14 Dec 2021
SQL injection in JDBC Appender in Apache Log4j V1
60RISK
open
GitHub PoC2
Sample docker-compose setup to show how this exploit works
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
roticagas/CVE-2021-44228-Demo
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC395
A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Metasploit600
SonicWall SMA 100 Series Authenticated Command Injection
CVE-2021-20039HIGH14 Dec 2021
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo
58RISK
open
GitHub PoC3
Check CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 625 / 2,596next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.