What this is
Exploits-DB.com is a free, ad-supported reference index of publicly disclosed vulnerabilities. Each entry is a call number: a CVE identifier, its severity, the affected vendor, and when it was published. Most people arrive already knowing the record they want, so the site is built like a printed catalogue rather than a landing page.
Where the data comes from
Entries are drawn from public vulnerability disclosure, principally the National Vulnerability Database and vendor advisories. We compile and present that record; we do not originate it. Upstream data is revised often, so an entry here is a pointer to the authoritative source, never a replacement for it.
What this is not
This is not a repository of attack tooling. We index and explain vulnerability metadata — identifiers, scores, vendors, dates — and we publish articles about reading it well. We do not host exploit payloads, and we draw that line deliberately; one of our own articles is about telling a proof-of-concept from a weaponised exploit. The audience we are writing for is the person who has to patch something by Friday.
Who maintains it
Exploits-DB.com is operated by Garnet Grid Consulting LLC. The index here is free, ad-supported, and has nothing for sale on it. A separate paid product, Exploit-DB.ai, adds risk scoring, watchlists, and alerting for teams that need them; the free reference stays free.
Corrections
If an entry here is wrong, stale, or misleading, we want to know — tell us at [email protected] and we will correct it. See also our contact page.