Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
78,056 exploits
GitHub PoC
Log4Shell (Cve-2021-44228) Proof Of Concept
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Quick and dirty scanner, hitting common ports looking for Log4Shell (CVE-2021-44228) vulnerability
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Regra ModSec para proteção log4j2 - CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
IOCs for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Detection script for CVE-2021-42278 and CVE-2021-42287
CVE-2021-42278HIGHunder attackransomware27 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1154627 Dec 2021
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2083726 Dec 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack25 Dec 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14871CRITICALunder attack25 Dec 2021
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
GitHub PoC2
This is a basic ROP based exploit for CVE 2020-14871. CVE 2020-14871 is a vulnerability in Sun Solaris systems libpam library, and exploitable over ssh
CVE-2020-14871CRITICALunder attack25 Dec 2021
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
GitHub PoC
this repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research
CVE-2021-44228CRITICALunder attackransomware25 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC100
Collection of materials relating to FORCEDENTRY
CVE-2021-30860HIGHunder attack25 Dec 2021
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catali
93RISK
open
GitHub PoC1
Log4Shell(CVE-2021-45046) Sandbox Signature
CVE-2021-45046CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC
general purpose workaround for the log4j CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228 检查工具
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
PoC for CVE-2021-44228.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC169
Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC5
Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC8
A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware24 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Metasploit600
TerraMaster TOS 4.2.15 or lower - RCE chain from unauthenticated to root via session crafting.
CVE-2021-4584124 Dec 2021
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta
18RISK
open
Metasploit600
TerraMaster TOS 4.2.15 or lower - RCE chain from unauthenticated to root via session crafting.
CVE-2021-4583924 Dec 2021
It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.
18RISK
open
Metasploit600
TerraMaster TOS 4.2.15 or lower - RCE chain from unauthenticated to root via session crafting.
CVE-2021-4583724 Dec 2021
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by send
23RISK
open
previouspage 623 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.