Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC
Log4Shell A test for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC19
Log4j Exploit Detection Logic for Zeek
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
taurusxin/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC11
Find Log4Shell CVE-2021-44228 on your system
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
log4j version 1 with a patch for CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC37
log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
tobiasoed/log4j-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC86
Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
A singular file to protect as many Minecraft servers and clients as possible from the Log4j exploit (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Some tools to help mitigating Apache Log4j 2 CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
Mass Check Vulnerable Log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
flxhaas/Scan-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
:boom: Automox Windows Agent Privilege Escalation Exploit
CVE-2021-4332613 Dec 2021
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISK
open
GitHub PoC
Mass recognition tool for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
CVE-2021-44228 - Apache log4j RCE quick test
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
log4j2 CVE-2021-44228 POC
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC102
Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
simple python scanner to check if your network is vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-4428 复现
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Research into the implications of CVE-2021-44228 in Spring based applications.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Simple tool for scanning entire directories for attempts of CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Log4Shell Docker Env
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Log4j Remote Code Injection (Apache Log4j 2.x < 2.15.0-rc2)
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 343 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.