exploit.cc compiles critical security information from authoritative public sources into one fast, searchable picture: vulnerability records, known-exploited status and exploit-prediction scores, kept continuously in sync with their upstreams and compiled into a view you can act on. Every field is traceable to the authority that published it, and nothing sits behind a login, a key or a paywall.
exploit.cc is an independent project. It is not an official property of any of its sources and is not affiliated with, endorsed by or operated by the CVE Program, MITRE, CISA or FIRST.
Nothing here is invented. Every field on a record page is compiled from a named public authority, and each authority remains authoritative for exactly what it provides.
CVE records come from the CVE Program's public repository of CVE JSON 5 documents. The description, CVSS scores and vector, CWE assignments, SSVC decision, affected products, references and solutions on a record page are read from that document, and the document itself is preserved byte for byte as ingested. Severity is the one derived value: it is computed from the numeric CVSS score, never taken from upstream prose, because CNAs and their own vectors disagree often enough that the score is the only defensible authority.
Known-exploited status comes from the CISA Known Exploited Vulnerabilities catalog, not from the CVE record. The catalog is the sole authority for the KEV badge, the date a record was added and its remediation due date.
CISA also publishes an SSVC assessment inside the CVE List record itself, through its role as an Authorized Data Publisher. Those decision points are a separate claim from catalog membership: an assessment that public proof-of-concept code exists is not a report that a vulnerability is being exploited in the wild. A record page shows both, labelled, and never merges them. Where CISA has published no assessment, the record page says so rather than reading the silence as a finding.
Exploit-prediction scores come from the Exploit Prediction Scoring System (EPSS), published by FIRST. Each scored record carries the current model's estimate of the probability it will be exploited in the wild within the next 30 days, together with its percentile across all scored CVEs, and the corpus is re-scored as each daily model run is published.
The National Vulnerability Database, operated by NIST, scores and analyses CVE records independently of the CNA that published them. A record page carries the NVD base score alongside the CNA score rather than in place of it, because the two can disagree and the disagreement is information. The NVD analysis status is shown as published, so a record still awaiting analysis is visibly awaiting analysis.
Red Hat rates the vulnerabilities that affect the products it ships, on its own four-level scale, and publishes those ratings as security data. That rating is a vendor assessment against Red Hat's own configurations, so it is shown as Red Hat's rating and never translated onto the CVSS severity ramp. A CVE with no Red Hat rating is usually a CVE that does not affect a Red Hat product.
Additional public feeds join the compilation as coverage expands.
The CVE List is polled every 15 minutes, the KEV catalog every 6 hours, and EPSS scores are refreshed as FIRST publishes each daily model run. A record typically lands here within one poll of being published upstream. Sync lag is the age of the newest upstream change indexed here, not the age of the last fetch, which would look healthy even while the feed returned nothing.
Consolidation is only worth anything if the result is fast and dependable:
Each source remains the authority for its own data, and each is named on the record pages that use it. The notices those sources require, and the licences they are used under, are reproduced in full on our Terms of Use.
Exploit-prediction scores are provided by the Exploit Prediction Scoring System (EPSS), developed and maintained by the EPSS Special Interest Group at FIRST.
exploit.cc is not an official property of any source it compiles, and no source has reviewed, endorsed or certified it. Where a record here disagrees with the authority that published it, the authority is correct and this index is behind; the next sync closes the gap.