Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
78,137 exploits
GitHub PoC276
Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
log4j version 1 with a patch for CVE-2021-44228 vulnerability
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC70
log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC37
log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
CVE-2021-44228 - Apache log4j RCE quick test
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
tobiasoed/log4j-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Professional Service scripts to aid in the identification of affected Java applications in TeamServer
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC62
.Net Assembly loader for the [CVE-2021-42287 - CVE-2021-42278] Scanner & Exploit noPac
CVE-2021-42287HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1,015
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
helsecert/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Simple tool for scanning entire directories for attempts of CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC11
Scanner for Log4j RCE CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Some files for red team/blue team investigations into CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
tica506/Siem-queries-for-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC6
Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Amaranese/CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware13 Dec 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware13 Dec 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware13 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 634 / 2,605next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.