Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
13,937 exploits
GitHub PoC8
fail2ban filter that catches attacks againts log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Some files for red team/blue team investigations into CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC19
Log4j Exploit Detection Logic for Zeek
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
Exploiting CVE-2021-42278 and CVE-2021-42287
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC2
:boom: Automox Windows Agent Privilege Escalation Exploit
CVE-2021-4332613 Dec 2021
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISK
open
GitHub PoC86
Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC62
.Net Assembly loader for the [CVE-2021-42287 - CVE-2021-42278] Scanner & Exploit noPac
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC2
This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Find log4j for CVE-2021-44228 on some places * Log4Shell
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Amaranese/CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware13 Dec 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC247
a fast check, if your server could be vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Log4J CVE-2021-44228 : Mitigation Cheat Sheet
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
CVE-2021-36260
CVE-2021-36260CRITICALunder attack13 Dec 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC3,424
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Using code search to help fix/mitigate log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC66
Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC38
Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC46
Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect in-depth (layered archives jar/zip/tar/war and scans for vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105). Binaries for Windows, Linux and OsX, but can be build on each platform supported by supported Golang.
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
Python script that sends CVE-2021-44228 log4j payload requests to url list
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Dockerized Go app for testing the CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC15
IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
lohanichaten/log4j-cve-2021-44228
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
pravin-pp/log4j2-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Poc of log4j2 (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Sample log4j shell exploit
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC49
Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
pythonic pure python RCE exploit for CVE-2021-44228 log4shell
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
An awesome curated list of repos for CVE-2021-44228. ``Apache Log4j 2``
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC8
CVE-2021-44228 (Log4Shell) Proof of Concept
CVE-2021-44228CRITICALunder attackransomware12 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 344 / 465next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.