
Exploits + Shellcode + GHDB v2026-08-12
exploitdb // Das offizielle Exploit-Database-Repository
Das Git-Repository der Exploit Database
Dies ist ein offizielles Repository der Exploit Database, einem Projekt, das von Offensive Security gesponsert wird. Unsere Repositories sind:
- Exploits & Shellcodes: gitlab.com/exploit-database/exploitdb
- Binary Exploits: gitlab.com/exploit-database/exploitdb-bin-sploits
- Papers: gitlab.com/exploit-database/exploitdb-papers
Die Exploit Database ist ein Archiv öffentlicher Exploits und der dazugehörigen verwundbaren Software, entwickelt für den Einsatz durch Penetrationstester und Sicherheitsforscher. Ihr Ziel ist es, als umfassendste Sammlung von Exploits, Shellcode und Papern zu dienen, die durch direkte Einsendungen, Mailinglisten und andere öffentliche Quellen zusammengetragen wurden, und diese in einer frei verfügbaren und leicht navigierbaren Datenbank bereitzustellen. Die Exploit Database ist eher ein Repository für Exploits und Proof-of-Concepts als für Advisories, was sie zu einer wertvollen Ressource für alle macht, die sofort verwertbare Daten benötigen. Weitere Informationen über das Projekt finden Sie hier (oben rechts -> About Exploit-DB) und hier (History).
Dieses Repository wird täglich mit den zuletzt hinzugefügten Einsendungen aktualisiert. Zusätzliche Ressourcen finden Sie in unserem Binary-Exploits-Repository.
Exploits befinden sich im Verzeichnis /exploits/, Shellcodes finden Sie im Verzeichnis /shellcodes/.
Lizenz
Dieses Projekt (und SearchSploit) wird unter der "GNU General Public License v2.0" veröffentlicht.
SearchSploit
In diesem Repository ist das Dienstprogramm SearchSploit enthalten, mit dem Sie Exploits, Shellcodes und Paper (sofern installiert) anhand eines oder mehrerer Begriffe durchsuchen können. Weitere Informationen finden Sie im SearchSploit-Handbuch.
Verwendung/Beispiel
kali@kali:~$ searchsploit -h
Usage: searchsploit [options] term1 [term2] ... [termN]
==========
Examples
==========
searchsploit afd windows local
searchsploit -t oracle windows
searchsploit -p 39446
searchsploit linux kernel 3.2 --exclude="(PoC)|/dos/"
searchsploit -s Apache Struts 2.0.0
searchsploit linux reverse password
searchsploit -j 55555 | jq
searchsploit --cve 2021-44228
For more examples, see the manual: https://www.exploit-db.com/searchsploit
=========
Options
=========
## Search Terms
-c, --case [term] Perform a case-sensitive search (Default is inSEnsITiVe)
-e, --exact [term] Perform an EXACT & order match on exploit title (Default is an AND match on each term) [Implies "-t"]
e.g. "WordPress 4.1" would not be detect "WordPress Core 4.1")
-s, --strict Perform a strict search, so input values must exist, disabling fuzzy search for version range
e.g. "1.1" would not be detected in "1.0 < 1.3")
-t, --title [term] Search JUST the exploit title (Default is title AND the file's path)
--exclude="term" Remove values from results. By using "|" to separate, you can chain multiple values
e.g. --exclude="term1|term2|term3"
--cve [CVE] Search for Common Vulnerabilities and Exposures (CVE) value
## Output
-j, --json [term] Show result in JSON format
-o, --overflow [term] Exploit titles are allowed to overflow their columns
-p, --path [EDB-ID] Show the full path to an exploit (and also copies the path to the clipboard if possible)
-v, --verbose Display more information in output
-w, --www [term] Show URLs to Exploit-DB.com rather than the local path
--id Display the EDB-ID value rather than local path
--disable-colour Disable colour highlighting in search results
## Non-Searching
-m, --mirror [EDB-ID] Mirror (aka copies) an exploit to the current working directory
-x, --examine [EDB-ID] Examine (aka opens) the exploit using $PAGER
## Non-Searching
-h, --help Show this help screen
-u, --update Check for and install any exploitdb package updates (brew, deb & git)
## Automation
--nmap [file.xml] Checks all results in Nmap's XML output with service version
e.g.: nmap [host] -sV -oX file.xml
=======
Notes
=======
* You can use any number of search terms
* By default, search terms are not case-sensitive, ordering is irrelevant, and will search between version ranges
* Use '-c' if you wish to reduce results by case-sensitive searching
* And/Or '-e' if you wish to filter results by using an exact match
* And/Or '-s' if you wish to look for an exact version match
* Use '-t' to exclude the file's path to filter the search results
* Remove false positives (especially when searching using numbers - i.e. versions)
* When using '--nmap', adding '-v' (verbose), it will search for even more combinations
* When updating or displaying help, search terms will be ignored
kali@kali:~$
kali@kali:~$ searchsploit afd windows local
---------------------------------------------------------------------------------------- -----------------------------------
Exploit Title | Path
---------------------------------------------------------------------------------------- -----------------------------------
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046) | windows_x86/local/40564.c
Microsoft Windows - 'afd.sys' Local Kernel (PoC) (MS11-046) | windows/dos/18755.c
Microsoft Windows - 'AfdJoinLeaf' Local Privilege Escalation (MS11-080) (Metasploit) | windows/local/21844.rb
Microsoft Windows 7 (x64) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040) | windows_x86-64/local/39525.py
Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040) | windows_x86/local/39446.py
Microsoft Windows XP - 'afd.sys' Local Kernel Denial of Service | windows/dos/17133.c
Microsoft Windows XP/2003 - 'afd.sys' Local Privilege Escalation (K-plugin) (MS08-066) | windows/local/6757.txt
Microsoft Windows XP/2003 - 'afd.sys' Local Privilege Escalation (MS11-080) | windows/local/18176.py
---------------------------------------------------------------------------------------- -----------------------------------
Shellcodes: No Result
kali@kali:~$
kali@kali:~$ searchsploit -p 39446
Exploit: Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
URL: https://www.exploit-db.com/exploits/39446
Path: /Users/b/Projects/git/forks/exploitdb/exploits/windows_x86/local/39446.py
Codes: N/A
Verified: False
File Type: Python script text executable, ASCII text
Copied EDB-ID #39446's path to the clipboard
kali@kali:~$
Installation
SearchSploit benötigt entweder "CoreUtils" oder "utilities" (z. B. bash, sed, grep, awk usw.), damit die Kernfunktionen funktionieren.
Die Selbstaktualisierungsfunktion erfordert git, und für die Nmap-XML-Option wird xmllint benötigt (im Paket libxml2-utils auf Debian-basierten Systemen enthalten).
Eine ausführlichere Anleitung finden Sie im SearchSploit-Handbuch.
Kali Linux
Exploit-DB/SearchSploit ist bereits in Kali-Linux enthalten. Eine Installationsmöglichkeit ist:
kali@kali:~$ sudo apt -y install exploitdb
HINWEIS: Optional können die zusätzlichen Pakete installiert werden:
kali@kali:~$ sudo apt -y install exploitdb-bin-sploits exploitdb-papers
Git
Kurz gesagt: Klonen Sie das Repository, fügen Sie die Binärdatei zu $PATH hinzu und bearbeiten Sie die Konfigurationsdatei, sodass sie den Git-Pfad widerspiegelt:
$ sudo git clone https://gitlab.com/exploit-database/exploitdb.git /opt/exploitdb
$ sudo ln -sf /opt/exploitdb/searchsploit /usr/local/bin/searchsploit
Homebrew
Wenn Sie homebrew (Paket, Formel) installiert haben, sind Sie mit dem folgenden Befehl einsatzbereit:
user@MacBook:~$ brew update && brew install exploitdb
Danksagung
Die folgenden Personen haben dies ermöglicht: