Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,211cataloged exploits
36,015CVEs with public exploitation
24,695lab-tested
78,137 exploits
GitHub PoC5
Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
log4j mitigation work
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Log4Shell CVE-2021-44228 Vulnerability Scanner and POC
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the presence of JndiLookup.class.
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4J checker for Apache CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Vulnmachines/log4j-cve-2021-44228
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
kannthu/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Log4Shell Proof of Concept (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2021-44228-Apache-Log4j
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Scanner recursivo de arquivos desenvolvido em Python 3 para localização e varredura de versões vulneráveis do Log4j2, contemplando análise interna de arquivos JAR (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 e CVE-2021-44832)
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC8
Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Simple webapp that is vulnerable to Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC12
Detect and fix log4j log4shell vulnerability (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
CVE-2021-44228 vulnerability in Apache Log4j library | Log4j vulnerability scanner on Windows machines.
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
log4j vulnerability wrapper scanner for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
CVE-2021-44848webappsmultiple16 Dec 2021
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack16 Dec 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware16 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-45046CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC9
Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
A one-stop repo/ information hub for all log4j vulnerability-related information.
CVE-2021-44228CRITICALunder attackransomware15 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 629 / 2,605next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.