Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
77,866 exploits
GitHub PoC2
Log4j2 CVE-2021-44228 复现和回显利用
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC45
Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class paths inside files
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
List of company advisories log4j
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
b-abderrahmane/CVE-2021-44228-playground
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Test the CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1,058
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHunder attackransomware11 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application.
CVE-2021-43798HIGHunder attack11 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC46
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798HIGHunder attack11 Dec 2021
Grafana path traversal
100RISK
open
GitHub PoC1,404
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
CVE-2021-42287HIGHunder attackransomware11 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
s4msec/CVE-2007-2447
CVE-2007-244711 Dec 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
Apache Log4j CVE-2021-44228 漏洞复现
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Небольшой мод направленный на устранение уязвимости CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Simple demo of CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC9
Public IoCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
vorburger/Log4j_CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
byteboycn/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
M1ngGod/CVE-2021-44228-Log4j-lookup-Rce
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC842
CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks
CVE-2021-44228CRITICALunder attackransomware11 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC108
Deploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
CVE-2021-44228 server-side fix for minecraft servers.
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
TheArqsz/CVE-2021-44228-PoC
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC35
Vulnerability CVE-2021-44228 checker
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1,140
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1,848
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC469
Remote Code Injection In Log4j
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC182
Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information
CVE-2021-44228CRITICALunder attackransomware10 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 632 / 2,596next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.