Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,137 exploits
GitHub PoC
municipalparkingservices/CVE-2021-44228-Scanner
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC16
ab0x90/CVE-2021-44228_PoC
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
CVE-2019-9581webappsphp14 Dec 2021
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISK
open
GitHub PoC
CVE-2021-44228 Response Scripts
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Metasploit600
SonicWall SMA 100 Series Authenticated Command Injection
CVE-2021-20039HIGH14 Dec 2021
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo
58RISK
open
Metasploit300
WordPress Modern Events Calendar SQLi Scanner
CVE-2021-2494613 Dec 2021
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
60RISK
open
GitHub PoC
Demonstration of CVE-2021-44228 with a possible strategic fix.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Compiling links of value i find regarding CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Amaranese/CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware13 Dec 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC8
Python3 script for scanning CVE-2021-44228 (Log4shell) vulnerable machines.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC3
Public IOCs about log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC247
a fast check, if your server could be vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack13 Dec 2021
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC3,421
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Using code search to help fix/mitigate log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Log4J CVE-2021-44228 : Mitigation Cheat Sheet
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC20
This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC37
OpenIOC rules to facilitate hunting for indicators of compromise
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 632 / 2,605next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.