Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Exploits + Shellcode + GHDB — exploitdb // O repositório oficial do Exploit-Database | Kitploit
Ferramentas/GitLabGitLab/exploit-database/exploitdb
ReconhecimentoFrameworks de ExploraçãoAnálise de VulnerabilidadesExploraçãoShellcodeColeta de InformaçõesTestes de PenetraçãoAprendizado e EducaçãoRecursos CuradosDesenvolvimento de Payloads
GitLab
25284112há 4 diasRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
exploit-database/exploitdb

Exploits + Shellcode + GHDB

exploitdb // O repositório oficial do Exploit-Database

Ver Repositório
Compartilhar
# O Repositório Git do Exploit Database

Este é um repositório oficial do [The Exploit Database](https://www.exploit-db.com/), um [projeto](https://www.offensive-security.com/community-projects/) patrocinado pela [Offensive Security](https://www.offensive-security.com/).
Nossos repositórios são:

  - Exploits e Shellcodes: [gitlab.com/exploit-database/exploitdb](https://gitlab.com/exploit-database/exploitdb)
  - Exploits Binários: [gitlab.com/exploit-database/exploitdb-bin-sploits](https://gitlab.com/exploit-database/exploitdb-bin-sploits)
  - Papers: [gitlab.com/exploit-database/exploitdb-papers](https://gitlab.com/exploit-database/exploitdb-papers)

O Exploit Database é um arquivo de exploits públicos e software vulnerável correspondente, desenvolvido para uso por testadores de penetração e pesquisadores de vulnerabilidades. Seu objetivo é servir como a coleção mais abrangente de [exploits](https://www.exploit-db.com/), [shellcodes](https://www.exploit-db.com/shellcodes) e [papers](https://www.exploit-db.com/papers) reunidos por meio de submissões diretas, listas de discussão e outras fontes públicas, e apresentá-los em um banco de dados gratuito e de fácil navegação. O Exploit Database é um repositório de exploits e Provas de Conceito, em vez de advisories, tornando-o um recurso valioso para aqueles que precisam de dados acionáveis imediatamente.
Você pode aprender mais sobre o projeto [aqui (Canto Superior Direito -> Sobre o Exploit-DB)](https://www.exploit-db.com/) e [aqui (História)](https://www.exploit-db.com/history).

Este repositório é atualizado diariamente com as submissões adicionadas mais recentemente. Quaisquer recursos adicionais podem ser encontrados em nosso [repositório de exploits binários](https://gitlab.com/exploit-database/exploitdb-bin-sploits).

Os exploits estão localizados no diretório [`/exploits/`](https://gitlab.com/exploit-database/exploitdb/tree/main/exploits), e os shellcodes podem ser encontrados no diretório [`/shellcodes/`](https://gitlab.com/exploit-database/exploitdb/tree/main/shellcodes).

- - -

## Licença

Este projeto (e o SearchSploit) é distribuído sob a "[GNU General Public License v2.0](https://gitlab.com/exploit-database/exploitdb/-/blob/main/LICENSE.md)".

- - -

# SearchSploit

Incluído com este repositório está o utilitário **SearchSploit**, que permitirá que você pesquise exploits, shellcodes e papers _(se instalados)_ usando um ou mais termos.
Para mais informações, consulte o **[manual do SearchSploit](https://www.exploit-db.com/searchsploit)**.

## Uso/Exemplo

```
kali@kali:~$ searchsploit -h
  Usage: searchsploit [options] term1 [term2] ... [termN]

==========
 Examples
==========
  searchsploit afd windows local
  searchsploit -t oracle windows
  searchsploit -p 39446
  searchsploit linux kernel 3.2 --exclude="(PoC)|/dos/"
  searchsploit -s Apache Struts 2.0.0
  searchsploit linux reverse password
  searchsploit -j 55555 | jq
  searchsploit --cve 2021-44228

  For more examples, see the manual: https://www.exploit-db.com/searchsploit

=========
 Options
=========
## Search Terms
   -c, --case     [term]      Perform a case-sensitive search (Default is inSEnsITiVe)
   -e, --exact    [term]      Perform an EXACT & order match on exploit title (Default is an AND match on each term) [Implies "-t"]
                                e.g. "WordPress 4.1" would not be detect "WordPress Core 4.1")
   -s, --strict               Perform a strict search, so input values must exist, disabling fuzzy search for version range
                                e.g. "1.1" would not be detected in "1.0 < 1.3")
   -t, --title    [term]      Search JUST the exploit title (Default is title AND the file's path)
       --exclude="term"       Remove values from results. By using "|" to separate, you can chain multiple values
                                e.g. --exclude="term1|term2|term3"
       --cve      [CVE]       Search for Common Vulnerabilities and Exposures (CVE) value

## Output
   -j, --json     [term]      Show result in JSON format
   -o, --overflow [term]      Exploit titles are allowed to overflow their columns
   -p, --path     [EDB-ID]    Show the full path to an exploit (and also copies the path to the clipboard if possible)
   -v, --verbose              Display more information in output
   -w, --www      [term]      Show URLs to Exploit-DB.com rather than the local path
       --id                   Display the EDB-ID value rather than local path
       --disable-colour       Disable colour highlighting in search results

## Non-Searching
   -m, --mirror   [EDB-ID]    Mirror (aka copies) an exploit to the current working directory
   -x, --examine  [EDB-ID]    Examine (aka opens) the exploit using $PAGER

## Non-Searching
   -h, --help                 Show this help screen
   -u, --update               Check for and install any exploitdb package updates (brew, deb & git)

## Automation
       --nmap     [file.xml]  Checks all results in Nmap's XML output with service version
                                e.g.: nmap [host] -sV -oX file.xml

=======
 Notes
=======
 * You can use any number of search terms
 * By default, search terms are not case-sensitive, ordering is irrelevant, and will search between version ranges
   * Use '-c' if you wish to reduce results by case-sensitive searching
   * And/Or '-e' if you wish to filter results by using an exact match
   * And/Or '-s' if you wish to look for an exact version match
 * Use '-t' to exclude the file's path to filter the search results
   * Remove false positives (especially when searching using numbers - i.e. versions)
 * When using '--nmap', adding '-v' (verbose), it will search for even more combinations
 * When updating or displaying help, search terms will be ignored

kali@kali:~$
kali@kali:~$ searchsploit afd windows local
---------------------------------------------------------------------------------------- -----------------------------------
 Exploit Title                                                                          |  Path
---------------------------------------------------------------------------------------- -----------------------------------
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)               | windows_x86/local/40564.c
Microsoft Windows - 'afd.sys' Local Kernel (PoC) (MS11-046)                             | windows/dos/18755.c
Microsoft Windows - 'AfdJoinLeaf' Local Privilege Escalation (MS11-080) (Metasploit)    | windows/local/21844.rb
Microsoft Windows 7 (x64) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)  | windows_x86-64/local/39525.py
Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)  | windows_x86/local/39446.py
Microsoft Windows XP - 'afd.sys' Local Kernel Denial of Service                         | windows/dos/17133.c
Microsoft Windows XP/2003 - 'afd.sys' Local Privilege Escalation (K-plugin) (MS08-066)  | windows/local/6757.txt
Microsoft Windows XP/2003 - 'afd.sys' Local Privilege Escalation (MS11-080)             | windows/local/18176.py
---------------------------------------------------------------------------------------- -----------------------------------
Shellcodes: No Result
kali@kali:~$
kali@kali:~$ searchsploit -p 39446
  Exploit: Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
      URL: https://www.exploit-db.com/exploits/39446
     Path: /Users/b/Projects/git/forks/exploitdb/exploits/windows_x86/local/39446.py
    Codes: N/A
 Verified: False
File Type: Python script text executable, ASCII text

Copied EDB-ID #39446's path to the clipboard
kali@kali:~$
```

- - -

## Instalação

O SearchSploit requer "CoreUtils" ou "utilitários" (ex.: `bash`, `sed`, `grep`, `awk`, etc.) para que os recursos principais funcionem.
A função de auto-atualização exigirá `git`, e para que a opção Nmap XML funcione, será necessário `xmllint` (encontrado no pacote `libxml2-utils` em sistemas baseados em Debian).

Você pode encontrar um **guia mais detalhado no [manual do SearchSploit](https://www.exploit-db.com/searchsploit)**.

**Kali Linux**

O Exploit-DB/SearchSploit já está empacotado dentro do Kali-Linux. Um método de instalação é:

```
kali@kali:~$ sudo apt -y install exploitdb
```

_NOTA: é opcional instalar os pacotes adicionais:_

```
kali@kali:~$ sudo apt -y install exploitdb-bin-sploits exploitdb-papers
```

**Git**

Em resumo, clone o repositório, adicione o binário ao `$PATH` e edite o arquivo de configuração para refletir o caminho do git:

```
$ sudo git clone https://gitlab.com/exploit-database/exploitdb.git /opt/exploitdb
$ sudo ln -sf /opt/exploitdb/searchsploit /usr/local/bin/searchsploit
```

**Homebrew**

Se você tiver o [homebrew](http://brew.sh/) ([pacote](https://github.com/Homebrew/homebrew-core/blob/master/Formula/exploitdb.rb), [fórmula](https://formulae.brew.sh/formula/exploitdb)) instalado, executar o seguinte deixará tudo configurado:

```
user@MacBook:~$ brew update && brew install exploitdb
```

- - -

## Créditos

As seguintes pessoas tornaram isso possível:

- [Offensive Security](https://www.offensive-security.com/)
- [@Unix-Ninja](https://github.com/unix-ninja)
- [@g0tmi1k](https://blog.g0tmi1k.com/)
Baixar ferramenta