Live index, updated daily from public sources

Every public exploit. One index.

Search CVE proof-of-concepts from GitHub, Exploit-DB, Metasploit and Nuclei, ranked by real-world exploit risk and checked for fake or booby-trapped repos.

149,756
CVEs with public PoCs
1,225
Critical risk
822
High risk
1,676
In CISA KEV
0
New in last 7 days
Database

Intelligence Catalog

CVE ID Exploit Risk EPSS Product Vulnerability PoCs
Loading dataset...
Developers

Free JSON API

Automate your threat intelligence with our daily-generated static endpoints. No authentication required.

Docs →
# Get top 200 highest-risk CVEs
curl -s https://securewithumer.github.io/Exploit-Index/api/v1/top-risk.json | jq .

# Fetch exact PoC links and factor breakdown for a specific CVE
curl -s https://securewithumer.github.io/Exploit-Index/api/v1/cve/CVE-2026-102115.json

# Atom feed for new exploits
https://securewithumer.github.io/Exploit-Index/feed.xml

Static & Fast

Pre-compiled on GitHub Pages means sub-100ms responses globally, never rate-limited.

Link-Safety Included

Every GitHub PoC URL in the API includes a trust_tier (Verified, Unknown, Suspicious, Malicious) to protect automated scrapers from malware.

FAQ

Common Questions

Do you host exploit code?

No. Exploit-Index is strictly a link-aggregator and search engine. We only store metadata and references to third-party repositories. We do not mirror, host, or execute any proof-of-concept code.

How is the Exploit Risk score calculated?

The 0-100 score is built by our risk engine every 24 hours. It heavily weights CISA KEV presence (known active exploitation) and FIRST EPSS probability. It then adds bonuses for the number of available PoCs, recent publication, and CVSS severity. You can read the full mathematical formula in our Scoring Documentation.

How does Link-Safety work?

Security researchers often face fake PoCs that contain infostealer malware. During our daily aggregation, a subagent scans the GitHub API for each repository. It checks account age, follower counts, forks, and repository contents for obfuscation or crypto wallet addresses. Repos are then bucketed into Verified, Unknown, Suspicious, or Malicious.

↑ ↓ Navigate ↵ Open Esc Close