Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,137 exploits
GitHub PoC1
helsecert/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC11
Scanner for Log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1,015
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC6
Exploiting CVE-2021-42278 and CVE-2021-42287
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC276
Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC62
.Net Assembly loader for the [CVE-2021-42287 - CVE-2021-42278] Scanner & Exploit noPac
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
Log4j Remote Code Injection (Apache Log4j 2.x < 2.15.0-rc2)
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC4
Log4Shell Docker Env
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Simple tool for scanning entire directories for attempts of CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC101
Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Some files for red team/blue team investigations into CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC8
fail2ban filter that catches attacks againts log4j CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
maxant/log4j2-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
CVE-2021-44228 - Apache log4j RCE quick test
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Find log4j for CVE-2021-44228 on some places * Log4Shell
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC86
Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43936CRITICALwebappsphp13 Dec 2021
Distributed Data Systems WebHM
60RISK
open
GitHub PoC291
PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
:boom: Automox Windows Agent Privilege Escalation Exploit
CVE-2021-4332613 Dec 2021
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISK
open
GitHub PoC
Professional Service scripts to aid in the identification of affected Java applications in TeamServer
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Just a personal proof of concept of CVE-2021-44228 on log4j2
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
tica506/Siem-queries-for-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC79
Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Log4Shell A test for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
taurusxin/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 633 / 2,605next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.