Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
78,056 exploits
GitHub PoC
i6c/MASS_CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware15 Dec 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC4
Oh no another one
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC
Replicating CVE-2021-45046
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
Metasploit600
SonicWall SMA 100 Series Authenticated Command Injection
CVE-2021-20039HIGH14 Dec 2021
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo
58RISK
open
GitHub PoC
Details : CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC439
Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
didoatanasov/cve-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC22
A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution (RCE) by logging a certain string. Given how ubiquitous this library is, the impact of the exploit (full server control), and how easy it is to exploit, the impact of this vulnerability is quite severe. We're calling it "Log4Shell" for short.
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC18
Log4j2 CVE-2021-44228 revshell, ofc it suck!!
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
CVE-2019-9581webappsphp14 Dec 2021
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISK
open
GitHub PoC
CVE-2021-44228 Response Scripts
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Sample docker-compose setup to show how this exploit works
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Demo project to evaluate Log4j2 Vulnerability | CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Little recap of the log4j2 remote code execution (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2022-23305CRITICAL14 Dec 2021
SQL injection in JDBC Appender in Apache Log4j V1
60RISK
open
GitHub PoC
roticagas/CVE-2021-44228-Demo
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC16
ab0x90/CVE-2021-44228_PoC
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Grafana8.x 任意文件读取
CVE-2021-43798HIGHunder attack14 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC4
A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC40
Tools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
Log4j Shield - fast ⚡, scalable and easy to use Log4j vulnerability CVE-2021-44228 finder and patcher
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC149
Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC10
Repo containing all info, scripts, etc. related to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC39
Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 629 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.