Exploits Database
  • Home
    • About the Exploit Database
  • Exploits
    • Remote Exploits
    • Web Application Exploits
    • Local & Privilege Escalation Exploits
    • PoC & Denial of Service Exploits
  • Shellcode
  • Papers
  • Google Hacking Database
  • Submit
  • Search

Offensive Security Exploit Database Archive

The Exploit Database – ultimate archive of Exploits, Shellcode, and Security Papers. New to the site? Learn about the Exploit Database.

0
Exploits Archived
  • The Exploit Database
    CVE Compliant

    The Exploit Database (EDB) is a CVE compliant archive of exploits and vulnerable software. A great resource for penetration testers, vulnerability researchers, and security addicts alike. Our goal is to collect exploits from various sources and concentrate them in one, easy to navigate database
    Download the Exploit Database Archive

  • Google Hacking Database

    The Google Hacking Database (GHDB) is a collection of interesting Google searches which find, identify or expose information which could be useful for penetration testers or security auditors such as advertised vulnerabilities, exposed credentials and more.
    Visit the Google Hacking Database

Remote Exploits

Email
Facebook
Twitter
GitHub
RSS

This exploit category includes exploits for remote services or applications, including client side exploits.

Date D A V Title Platform Author
2016-04-01 Exploit Code Downloads - Waiting verification PHP <= 7.0.4/5.5.33 - SNMP Format String Exploit multiple Andrew Kramer
2016-03-31 Exploit Code Downloads - Verified Apache Jetspeed Arbitrary File Upload java metasploit
2012-12-30 Exploit Code Downloads - Verified LShell <= 0.9.15 - Remote Code Execution linux drone
2016-03-30 Exploit Code Downloads Download Vulnerable Application Verified ATutor 2.2.1 Directory Traversal / Remote Code Execution php metasploit
2016-03-30 Exploit Code Downloads - Waiting verification Metaphor - Stagefright Exploit with ASLR Bypass android NorthBit
2016-03-29 Exploit Code Downloads - Verified Adobe Flash - Object.unwatch Use-After-Free Exploit multiple Google Securit.
2016-03-23 Exploit Code Downloads - Waiting verification Multiple CCTV-DVR Vendors - Remote Code Execution hardware K1P0D

Web Application Exploits

This exploit category includes exploits for web applications.

Date D A V Title Platform Author
2016-04-04 Exploit Code Downloads - Waiting verification PQI Air Pen Express 6W51-0000R2 and 6W51-0000R2XXX - Multiple Vulnerabilities hardware Orwelllabs
2016-04-01 Exploit Code Downloads Download Vulnerable Application Verified WordPress Advanced Video Plugin 1.0 - Local File Inclusion (LFI) php evait security.
2016-03-31 Exploit Code Downloads - Waiting verification MOBOTIX Video Security Cameras - CSRF Add Admin Exploit hardware LiquidWorm
2016-03-31 Exploit Code Downloads - Waiting verification Apache OpenMeetings 1.9.x - 3.1.0 - ZIP File path Traversal linux Andreas Lindh
2016-03-27 Exploit Code Downloads Download Vulnerable Application Waiting verification Wordpress Plugin IMDb Profile Widget 1.0.8 - Local File Inclusion php CrashBandicot
2016-03-27 Exploit Code Downloads Download Vulnerable Application Waiting verification WordPress Photocart Link Plugin 1.6 - Local File Inclusion php CrashBandicot
2016-03-30 Exploit Code Downloads Download Vulnerable Application Verified CubeCart 6.0.10 - Multiple Vulnerabilities php High-Tech Brid.

Local & Privilege Escalation Exploits

This exploit category includes local exploits or privilege escalation exploits.

Date D A V Title Platform Author
2016-04-04 Exploit Code Downloads Download Vulnerable Application Waiting verification Hexchat IRC Client 2.11.0 - Directory Traversal multiple PizzaHatHacker
2016-03-28 Exploit Code Downloads - Verified FireEye - Privilege Escalation to root from Malware Input Processor (uid=mip) linux Google Securit.
2016-03-28 Exploit Code Downloads - Verified Cogent Datahub <= 7.3.9 Gamma Script Elevation of Privilege windows mr_me
2016-03-23 Exploit Code Downloads - Verified OS X / iOS Suid Binary Logic Error Kernel Code Execution multiple Google Securit.
2016-03-22 Exploit Code Downloads Download Vulnerable Application Verified CoolPlayer (Standalone) build 2.19 - .m3u Stack Overflow windows Charley Celice
2016-03-21 Exploit Code Downloads - Verified Windows - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032) windows Google Securit.
2016-03-21 Exploit Code Downloads Download Vulnerable Application Verified Internet Download Manager 6.25 Build 14 - 'Find file' Unicode SEH Exploit windows Rakan Alotaibi

PoC & Denial of Service Exploits

This exploit category includes proof of concept code or code that results in a denial of service or application crash.

Date D A V Title Platform Author
2016-04-04 Exploit Code Downloads Download Vulnerable Application Waiting verification Xion Audio Player <= 1.5 (build 160) - .mp3 Crash PoC windows Charley Celice
2016-04-04 Exploit Code Downloads Download Vulnerable Application Waiting verification Hexchat IRC Client 2.11.0 - CAP LS Handling Buffer Overflow multiple PizzaHatHacker
2016-04-01 Exploit Code Downloads - Verified Windows Kernel - Bitmap Use-After-Free windows Nils Sommer
2016-04-01 Exploit Code Downloads - Verified Windows Kernel - NtGdiGetTextExtentExW Out-of-Bounds Memory Read windows Nils Sommer
2016-04-01 Exploit Code Downloads - Verified Adobe Flash - URLStream.readObject Use-After-Free multiple Google Securit.
2016-04-01 Exploit Code Downloads - Verified Adobe Flash - TextField.maxChars Use-After-Free multiple Google Securit.
2016-04-01 Exploit Code Downloads - Verified Android - ih264d_process_intra_mb Memory Corruption android Google Securit.

Exploit Shellcode Archive

This category includes archived shellcode.

Date D Title Platform Author
2016-03-28 Exploit Code Downloads Linux/x86_x64 - execve(/bin/sh) - 25 bytes lin_x86-64 Ajith Kp
2016-03-28 Exploit Code Downloads Linux/x86_x64 - execve(/bin/bash) - 33 bytes lin_x86-64 Ajith Kp
2016-03-24 Exploit Code Downloads Linux/x86_x64 - execve(/bin/sh) - 26 bytes lin_x86-64 Ajith Kp
2016-03-02 Exploit Code Downloads x86 Windows Null-Free Download & Run via WebDAV Shellcode (96 bytes) win32 Sean Dillon
2016-02-26 Exploit Code Downloads Linux/ARM - Connect back to {ip:port} with /bin/sh - 95 bytes arm Xeon
2016-02-01 Exploit Code Downloads x86_64 Linux shell_reverse_tcp with Password - Polymorphic Version v2 lin_x86-64 Sathish kumar
2016-02-01 Exploit Code Downloads Linux x86 Download & Execute Shellcode lin_x86 B3mB4m

Archived Security Papers

Archived security papers in all languages.

Date D Title Author
2016-04-04 Exploit Code Downloads Exploiting Buffer Overflows on MIPS Architecture Lyon Yang
2016-03-07 Exploit Code Downloads Metaphor - A (real) real-­life Stagefright exploit NorthBit
2016-03-01 Exploit Code Downloads [Hebrew] Digital Whisper Security Magazine #70 cp77fk4r & Und.
2016-02-11 Exploit Code Downloads NDI5aster - Privilege Escalation through NDIS 5.x Filter Intermediate Drivers Kyriakos Econo.
2016-02-10 Exploit Code Downloads The Most Forgotten Web Vulnerabilities WhiteCollarGro.
2016-02-01 Exploit Code Downloads [Hebrew] Digital Whisper Security Magazine #69 cp77fk4r & Und.
2016-01-21 Exploit Code Downloads [Spanish] Windows Heap Overflow Exploitation - Exploiting a Custom Heap Under Windows 7 Christian Guzm.

offsec-logo-gray-trans
kali-logo-gray-trans
edb-logo-gray-trans
nethunter-logo-gray-trans
© Copyright 2016 Exploit Database