Blog RSSExploits RSSFacebook
CVE Certified

The Exploit Database

GHDB

 

The Exploit Database (EDB) – an ultimate archive of exploits and vulnerable software. A great resource for penetration testers, vulnerability researchers, and security addicts alike. Our aim is to collect exploits from submittals and mailing lists and concentrate them in one, easy to navigate database.


Remote Exploits

Date D   Description Plat. Author
2026-02-11   Windows 10.0.17763.7009 - spoofing vulnerability 180 REMOTE beatrizfn
2026-02-04   windows 10/11 - NTLM Hash Disclosure Spoofing 82 REMOTE beatrizfn
2026-02-04   Redis 8.0.2 - RCE 130 REMOTE Beatriz Fresno Naumova
2026-02-04   Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE 83 REMOTE Beatriz Fresno Naumova
2025-09-16   Ilevia EVE X1/X5 Server 4.7.18.0.eden - Reverse Rootshell 324 REMOTE LiquidWorm
2025-09-16   ClipBucket 5.5.0 - Arbitrary File Upload 233 REMOTE Mukundsinh Solanki (r00td3str0y3r)
2025-09-16   ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF) 145 REMOTE Mukundsinh Solanki (r00td3str0y3r)
2025-09-16   HTTP/2 2.0 - Denial Of Service (DOS) 140 REMOTE Madhusudhan Rajappa
2025-09-16   HTMLDOC 1.9.13 - Stack Buffer Overflow 125 REMOTE wulfgarpro
2025-08-26   GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE) 239 REMOTE Giorgi Dograshvili

Local Exploits

Date D   Description Plat. Author
2026-04-10   NetBT e-Fatura - Privilege Escalation 15 LOCAL seccops
2026-04-09   ZSH 5.9 - RCE 11 LOCAL sinanadilrana
2026-04-08   7-Zip 24.00 - Directory Traversal 14 LOCAL Mohammed Idrees Banyamer
2026-04-08   SQLite 3.50.1 - Heap Overflow 15 LOCAL Mohammed Idrees Banyamer
2026-04-08   Microsoft MMC MSC EvilTwin - Local Admin Creation 15 LOCAL Mohammed Idrees Banyamer
2026-04-06   is-localhost-ip 2.0.0 - SSRF 17 LOCAL nu11secur1ty
2026-04-06   Windows Kernel - Elevation of Privilege 11 LOCAL E1 Coders
2026-04-06   Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation 17 LOCAL nu11secur1ty
2026-02-11   glibc 2.38 - Buffer Overflow 59 LOCAL Beatriz Fresno Naumova
2026-02-04   Docker Desktop 4.44.3 - Unauthenticated API Exposure 58 LOCAL aprillefou

Web Applications

Date D   Description Plat. Author
2026-04-10   D-Link DIR-650IN - Authenticated Command Injection 13 WEB Sanjay Singh
2026-04-09   React Server 19.2.0 - Remote Code Execution 12 WEB danieljavanrad
2026-04-09   RomM 4.4.0 - XSS_CSRF Chain 12 WEB mmohammedheshamm
2026-04-09   Jumbo Website Manager - Remote Code Execution 12 WEB Mirabbas Ağalarov
2026-04-08   FortiWeb 8.0.2 - Remote Code Execution 31 WEB Mohammed Idrees Banyamer
2026-04-08   xibocms 3.3.4 - RCE 14 WEB complexusprada
2026-04-08   Horilla v1.3 - RCE 13 WEB nakleh
2026-04-06   Fortinet FortiWeb v8.0.1 - Auth Bypass 17 WEB nu11secur1ty
2026-04-06   ASP.net 8.0.10 - Bypass 16 WEB Mohammed Idrees Banyamer
2026-04-06   Grafana 11.6.0 - SSRF 16 WEB Beatriz Fresno Naumova

DoS/PoC

Date D   Description Plat. Author
2025-07-28   Xlight FTP 1.1 - Denial Of Service (DOS) 127 DOS Fernando Mengali
2024-08-28   Windows TCP/IP - RCE Checker and Denial of Service 122 DOS Photubias
2024-03-28   RouterOS 6.40.5 - 6.44 and 6.48.1 - 6.49.10 - Denial of Service 113 DOS ice-wzl
2024-02-26   Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'DoS' 105 DOS hyp3rlinx
2024-02-19   XAMPP - Buffer Overflow POC 104 DOS Talson
2024-02-13   VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service 103 DOS LiquidWorm
2024-02-09   Elasticsearch - StackOverflow DoS 119 DOS TOUHAMI Kasbaoui
2024-02-02   Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS 129 DOS LiquidWorm
2023-10-09   OpenPLC WebServer 3 - Denial of Service 85 DOS Kai Feng
2023-10-09   Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service 104 DOS LiquidWorm

Shellcode

Date D   Description Plat. Author
2025-08-04   Linux/x86_64 - execve(_/bin/sh__[_-c__cmd]_NULL) Arbitrary Command Execution She 156 SHELLCODE Muzaffer Umut ŞAHİN
2025-05-21   Windows 11 x64 - Reverse TCP Shellcode (564 bytes) 231 SHELLCODE Victor Huerlimann
2025-05-21   Linux/x86 - Reverse TCP Shellcode (95 bytes) 159 SHELLCODE Al Baradi Joy
2025-05-21   Linux/x86-64 - execve(_/bin/sh_) Shellcode (36 bytes) 132 SHELLCODE Sayan Ray
2023-09-08   Windows/x64 - PIC Null-Free TCP Reverse Shell Shellcode (476 Bytes) 105 SHELLCODE Senzee
2023-08-21   Linux/x64 - memfd_create ELF loader Shellcode (170 bytes) 121 SHELLCODE Ivan Nikolsky
2023-07-28   Windows/x64 - PIC Null-Free Calc.exe Shellcode (169 Bytes) 116 SHELLCODE Senzee
2023-04-25   Windows/x64 - Delete File shellcode / Dynamic PEB method null-free Shellcode 111 SHELLCODE Nayani
2023-04-05   Linux/x86_64 - bash Shellcode with xor encoding 100 SHELLCODE Jeenika Anadani
2023-04-03   Windows/x86 - Create Administrator User / Dynamic PEB & EDT method null-free She 119 SHELLCODE Xavi Beltran

Papers

Date D   Description Plat. Author
2018-11-16   The Powerful Resource of PHP Stream Wrappers 741 PAPERS Netsparker
2018-11-01   Phrack: Viewer Discretion Advised: (De)coding an iOS Kernel Vulnerability (Adam 671 PAPERS phrack
2018-10-09   A Red Teamer’s guide to pivoting 616 PAPERS Artem Kondratenko
2018-10-08   Phrack: Twenty years of Escaping the Java Sandbox (Ieu Eauvidoum & disk noise) 1600 PAPERS phrack
2018-01-15   Phrack: .NET Instrumentation via MSIL bytecode injection (Antonio "s4tan" Parata 1475 PAPERS phrack
2017-08-28   Abusing Token Privileges For LPE 994 PAPERS drone and breenmachine
2017-01-12   OpenSSL - Weak KDF 1040 PAPERS anonymous
2014-08-27   SSDP Amplification Scanner 786 PAPERS SaMaN
2014-06-26   [Hacking-Contest] SSH Server wrapper 763 PAPERS Jakob Lell
2012-03-20   Full MSSQL Injection PWNage 1014 PAPERS CWH Underground