The Exploit Database
The Exploit Database (EDB) – an ultimate archive of exploits and vulnerable software. A great resource for penetration testers, vulnerability researchers, and security addicts alike. Our aim is to collect exploits from submittals and mailing lists and concentrate them in one, easy to navigate database.
Remote Exploits
| Date | D | Description | Plat. | Author | |
|---|---|---|---|---|---|
| 2026-02-11 |
|
Windows 10.0.17763.7009 - spoofing vulnerability | 110 | REMOTE | beatrizfn |
| 2026-02-04 |
|
windows 10/11 - NTLM Hash Disclosure Spoofing | 69 | REMOTE | beatrizfn |
| 2026-02-04 |
|
Redis 8.0.2 - RCE | 111 | REMOTE | Beatriz Fresno Naumova |
| 2026-02-04 |
|
Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE | 75 | REMOTE | Beatriz Fresno Naumova |
| 2025-09-16 |
|
Ilevia EVE X1/X5 Server 4.7.18.0.eden - Reverse Rootshell | 316 | REMOTE | LiquidWorm |
| 2025-09-16 |
|
ClipBucket 5.5.0 - Arbitrary File Upload | 228 | REMOTE | Mukundsinh Solanki (r00td3str0y3r) |
| 2025-09-16 |
|
ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF) | 141 | REMOTE | Mukundsinh Solanki (r00td3str0y3r) |
| 2025-09-16 |
|
HTTP/2 2.0 - Denial Of Service (DOS) | 134 | REMOTE | Madhusudhan Rajappa |
| 2025-09-16 |
|
HTMLDOC 1.9.13 - Stack Buffer Overflow | 118 | REMOTE | wulfgarpro |
| 2025-08-26 |
|
GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE) | 236 | REMOTE | Giorgi Dograshvili |
Local Exploits
| Date | D | Description | Plat. | Author | |
|---|---|---|---|---|---|
| 2026-04-06 |
|
is-localhost-ip 2.0.0 - SSRF | 6 | LOCAL | nu11secur1ty |
| 2026-04-06 |
|
Windows Kernel - Elevation of Privilege | 2 | LOCAL | E1 Coders |
| 2026-04-06 |
|
Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation | 4 | LOCAL | nu11secur1ty |
| 2026-02-11 |
|
glibc 2.38 - Buffer Overflow | 50 | LOCAL | Beatriz Fresno Naumova |
| 2026-02-04 |
|
Docker Desktop 4.44.3 - Unauthenticated API Exposure | 50 | LOCAL | aprillefou |
| 2025-09-16 |
|
Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP - Elevation of P | 175 | LOCAL | Milad Karimi (Ex3ptionaL) |
| 2025-09-16 |
|
Mbed TLS 3.6.4 - Use-After-Free | 98 | LOCAL | Byte Reaper |
| 2025-08-26 |
|
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure | 119 | LOCAL | Giorgi Dograshvili |
| 2025-08-11 |
|
Microsoft Windows - Storage QoS Filter Driver Checker | 77 | LOCAL | nu11secur1ty |
| 2025-08-03 |
|
Microsoft Virtual Hard Disk (VHDX) 11 - Remote Code Execution (RCE) | 149 | LOCAL | nu11secur1ty |
Web Applications
| Date | D | Description | Plat. | Author | |
|---|---|---|---|---|---|
| 2026-04-06 | ![]() |
Fortinet FortiWeb v8.0.1 - Auth Bypass | 3 | WEB | nu11secur1ty |
| 2026-04-06 | ![]() |
ASP.net 8.0.10 - Bypass | 7 | WEB | Mohammed Idrees Banyamer |
| 2026-04-06 | ![]() |
Grafana 11.6.0 - SSRF | 5 | WEB | Beatriz Fresno Naumova |
| 2026-04-06 | ![]() |
Zhiyuan OA - arbitrary file upload leading | 4 | WEB | Beatriz Fresno Naumova |
| 2026-04-06 | ![]() |
WBCE CMS 1.6.4 - Remote Code Execution | 3 | WEB | red |
| 2026-04-06 | ![]() |
RiteCMS 3.1.0 - Authenticated Remote Code Execution | 2 | WEB | red |
| 2026-04-06 | ![]() |
WordPress Madara - Local File Inclusion | 7 | WEB | Beatriz Fresno Naumova |
| 2026-03-03 | ![]() |
WordPress Backup Migration 1.3.7 - Remote Command Execution | 72 | WEB | dangwenjing |
| 2026-03-03 | ![]() |
mailcow 2025-01a - Host Header Password Reset Poisoning | 28 | WEB | alvarez |
| 2026-03-03 | ![]() |
Easy File Sharing Web Server v7.2 - Buffer Overflow | 30 | WEB | diogo |
DoS/PoC
| Date | D | Description | Plat. | Author | |
|---|---|---|---|---|---|
| 2025-07-28 | ![]() |
Xlight FTP 1.1 - Denial Of Service (DOS) | 123 | DOS | Fernando Mengali |
| 2024-08-28 | ![]() |
Windows TCP/IP - RCE Checker and Denial of Service | 115 | DOS | Photubias |
| 2024-03-28 | ![]() |
RouterOS 6.40.5 - 6.44 and 6.48.1 - 6.49.10 - Denial of Service | 108 | DOS | ice-wzl |
| 2024-02-26 | ![]() |
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'DoS' | 100 | DOS | hyp3rlinx |
| 2024-02-19 | ![]() |
XAMPP - Buffer Overflow POC | 97 | DOS | Talson |
| 2024-02-13 | ![]() |
VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) - Remote Denial Of Service | 97 | DOS | LiquidWorm |
| 2024-02-09 | ![]() |
Elasticsearch - StackOverflow DoS | 112 | DOS | TOUHAMI Kasbaoui |
| 2024-02-02 | ![]() |
Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS | 120 | DOS | LiquidWorm |
| 2023-10-09 | ![]() |
OpenPLC WebServer 3 - Denial of Service | 79 | DOS | Kai Feng |
| 2023-10-09 | ![]() |
Tinycontrol LAN Controller v3 (LK3) 1.58a - Remote Denial Of Service | 98 | DOS | LiquidWorm |
Shellcode
Papers
| Date | D | Description | Plat. | Author | |
|---|---|---|---|---|---|
| 2018-11-16 | ![]() |
The Powerful Resource of PHP Stream Wrappers | 729 | PAPERS | Netsparker |
| 2018-11-01 | ![]() |
Phrack: Viewer Discretion Advised: (De)coding an iOS Kernel Vulnerability (Adam | 661 | PAPERS | phrack |
| 2018-10-09 | ![]() |
A Red Teamer’s guide to pivoting | 606 | PAPERS | Artem Kondratenko |
| 2018-10-08 | ![]() |
Phrack: Twenty years of Escaping the Java Sandbox (Ieu Eauvidoum & disk noise) | 1594 | PAPERS | phrack |
| 2018-01-15 | ![]() |
Phrack: .NET Instrumentation via MSIL bytecode injection (Antonio "s4tan" Parata | 1461 | PAPERS | phrack |
| 2017-08-28 | ![]() |
Abusing Token Privileges For LPE | 986 | PAPERS | drone and breenmachine |
| 2017-01-12 | ![]() |
OpenSSL - Weak KDF | 1036 | PAPERS | anonymous |
| 2014-08-27 | ![]() |
SSDP Amplification Scanner | 781 | PAPERS | SaMaN |
| 2014-06-26 | ![]() |
[Hacking-Contest] SSH Server wrapper | 756 | PAPERS | Jakob Lell |
| 2012-03-20 | ![]() |
Full MSSQL Injection PWNage | 1006 | PAPERS | CWH Underground |



