exploit.cc compiles security information published by other organisations and presents it in one place. It is free, it has no accounts, and it is a reference rather than an authority. These Terms cover what that means in practice: what the data is and is not, what you may do with it, and where the responsibility sits when it is wrong.
Section 3 is the one to read if you read only one. It explains why a missing score, a stale record or an absent exploitation flag is a normal state of a compiled index rather than a finding about the world.
These Terms of Use (the "Terms") are an agreement between you and EVECS, LLC ("exploit.cc", "we", "us") governing your access to and use of the website at https://exploit.cc and its subdomains (the "Site").
The Site is free and open. There is nothing to sign up for and no button to click, so your use of the Site is your acceptance of these Terms. If you do not accept them, do not use the Site.
Our Privacy Policy and Cookie Policy form part of these Terms. Where they conflict with these Terms on a privacy question, those documents control.
If you use the Site on behalf of an organisation, you confirm you are authorised to accept these Terms for it, and "you" includes that organisation.
exploit.cc consolidates security information published by other organisations into one searchable place. Vulnerability records, exploitation status, scoring and vendor assessments are compiled from public sources, kept in sync with those sources, and presented together so they can be read side by side.
We are a compiler, not an authority. We do not assign identifiers, score vulnerabilities, decide what is being exploited, or research vulnerabilities ourselves. Every substantive field on this Site originates with the organisation named beside it, and that organisation remains the authority for it. Section 7 sets out those sources and the attribution they require.
exploit.cc is an independent project. It is not an official property of any of its sources, and it is not affiliated with, endorsed by, certified by or operated by any of them.
We may change, add to, restrict or withdraw any part of the Site at any time, including the sources compiled, the fields shown and the features available. The Site is provided free of charge and nothing here commits us to keeping any part of it available.
This is the section that matters most, so it is stated plainly rather than in the disclaimer voice used further down.
Verify against the source before you act. The authority that published a field is the record of it. Where this Site and the source disagree, the source is right and this Site is behind.
Nothing on the Site is professional advice of any kind. It is not security advice, legal advice, compliance advice, investment advice or a recommendation to take or refrain from any action. No relationship of adviser and client, or of any similar kind, arises from your use of the Site.
The Site is a reference to be used alongside your own judgement and your own testing. It is not a substitute for either. In particular, do not use it as the sole basis for:
You are solely responsible for what you do with the information here, for confirming it against its source, and for the consequences either way.
You must not, and must not permit anyone else to:
Reporting a security problem in the Site itself is welcome, and is not a breach of these Terms. Write to contact@exploit.cc.
Automated access is not forbidden, and the Site publishes a robots.txt that says which paths are open to crawlers. What is forbidden is automated access that costs us more than it costs you.
robots.txt, and any rate limit, block or challenge the Site applies.We may block, throttle or challenge any traffic that threatens the availability or cost of the Site, with no notice and at our discretion. This is an operational measure, not a penalty, and it carries no implication of wrongdoing.
Everything substantive on this Site was published by one of the organisations below. Each remains the authority for what it publishes. The notices in this section are here because those sources require them, and they apply to the material reproduced on this Site exactly as they apply at the source.
Quoted blocks are reproduced verbatim from the licensor's own document. They are not our words and are not edited.
CVE™ records, and the CWE™ weakness identifiers and names shown alongside them, are published by The MITRE Corporation.
Copyright © 1999-2026, The MITRE Corporation. CVE™ is used under this licence:
CVE Terms of Use, cve.orgCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
Copyright © 2006-2026, The MITRE Corporation. CWE™ is used under this licence:
CWE Terms of Use, cwe.mitre.orgCWE™ is free to use by any organization or individual for any research, development, and/or commercial purposes, per these CWE Terms of Use. Accordingly, The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. Any copy you make for such purposes is authorized on the condition that you reproduce MITRE's copyright designation and this license in any such copy. CWE is a trademark of The MITRE Corporation.
CVE™ is a trademark of The MITRE Corporation. exploit.cc is not an official CVE Program property and is not affiliated with, endorsed by or operated by the CVE Program or MITRE.
Red Hat security data: Copyright © Red Hat, Inc. All rights reserved. Licensed under CC BY 4.0. Original data. Modified by exploit.cc.
Those are the only two outbound links this Site is obliged to carry. CC BY asks for the creator, the notice as supplied, the licence, a link to the original and the fact that the data was modified, and it allows all of that to sit on one page rather than beside every reading.
This product uses the NVD API but is not endorsed or certified by the NVD. CVSS is owned by FIRST.Org, Inc. and used by permission.
NVD data is produced by the National Institute of Standards and Technology, an agency of the United States government, and is in the public domain.
Known-exploited status comes from the Known Exploited Vulnerabilities catalog published by the Cybersecurity and Infrastructure Security Agency, a work of the United States government in the public domain. Exploit-prediction scores come from the Exploit Prediction Scoring System, developed by the EPSS Special Interest Group at FIRST and published as an open dataset. Neither requires attribution. Both are named here, and on the record pages that use them, because a claim that a vulnerability is being exploited, or is likely to be, means nothing without its author's name attached. Nothing on this Site is endorsed or certified by either organisation.
Naming a source is attribution, not endorsement. No organisation named on this Site has reviewed, approved, certified or endorsed exploit.cc, its compilation of their data, or anything you do with it. Where a source's own terms govern its data, those terms reach you through this Site unchanged, and nothing in these Terms adds to or subtracts from them.
Two different things sit on this Site and they carry different rights.
The underlying records belong to their publishers and are governed by the terms set out in section 7. Nothing in these Terms adds to or subtracts from those terms, and nothing here restricts your obtaining the same records directly from their sources under them.
Everything we made is ours. The Site's design, code, layout, branding, name, logo, original text, and the selection, arrangement, normalisation and presentation that make a compilation out of separate sources, are owned by EVECS, LLC and protected as such. We grant you a personal, revocable, non-exclusive licence to view and use the Site for your own reference, internal business use, research or reporting, and to quote from it with attribution.
That licence does not extend to reproducing the compilation as a whole or any substantial part of it, to building a competing compilation from it, or to using our name or logo without our written permission. Truthful factual reference to exploit.cc as a source is always permitted and needs no permission.
If you send us feedback or suggestions, we may use them without restriction and without owing you anything for them.
Records on the Site contain references published by their sources, and those references link to sites we do not control: vendor advisories, mailing lists, code repositories, exploit write-ups and personal pages. We do not review, endorse or vouch for any of them, and a link appearing in a record is not a statement that its destination is safe, accurate, lawful or still under the control of whoever published it. Following a reference is at your own risk, and what happens there is governed by that site's terms, not ours.
THE SITE AND EVERYTHING ON IT ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EVECS, LLC AND ITS SUPPLIERS AND LICENSORS DISCLAIM ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
WITHOUT LIMITING THAT, WE DO NOT WARRANT THAT THE INFORMATION ON THE SITE IS ACCURATE, COMPLETE, CURRENT OR FREE OF ERROR; THAT IT REFLECTS THE CURRENT STATE OF ANY UPSTREAM SOURCE; THAT THE SITE WILL BE AVAILABLE, UNINTERRUPTED, TIMELY OR SECURE; OR THAT IT WILL MEET YOUR REQUIREMENTS OR BE FIT FOR ANY PARTICULAR PURPOSE OF YOURS.
Some jurisdictions do not allow the exclusion of certain warranties. Where that is the case, the exclusions above apply to the fullest extent the law allows and no further, and nothing in these Terms affects a right you have that cannot be waived.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, EVECS, LLC AND ITS MEMBERS, OFFICERS, EMPLOYEES, AGENTS, SUPPLIERS AND LICENSORS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS OPPORTUNITY OR BUSINESS INTERRUPTION, OR FOR ANY SECURITY INCIDENT, BREACH, COMPROMISE, DOWNTIME OR REGULATORY CONSEQUENCE, ARISING OUT OF OR RELATED TO THE SITE OR THESE TERMS, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY OR ANY OTHER THEORY, AND EVEN IF WE HAVE BEEN ADVISED THAT SUCH DAMAGES ARE POSSIBLE.
THIS INCLUDES, WITHOUT LIMITATION, ANY LOSS ARISING FROM INFORMATION ON THE SITE BEING INACCURATE, INCOMPLETE, OUT OF DATE, MISSING OR MISUNDERSTOOD, OR FROM ANY ACTION TAKEN OR NOT TAKEN IN RELIANCE ON IT.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THE SITE OR THESE TERMS WILL NOT EXCEED ONE HUNDRED U.S. DOLLARS (US $100).
These limits apply even if a remedy fails of its essential purpose. They reflect the allocation of risk on which the Site is offered: it is provided free of charge, to everyone, with no account and no fee, and it could not be offered on those terms if publishing a compiled public record carried unlimited liability for how it is read.
Nothing in this section limits liability that cannot be limited under applicable law, including liability for fraud, for wilful misconduct, or for death or personal injury caused by negligence. Some jurisdictions do not allow certain limitations, in which case they apply to the fullest extent the law allows.
You will defend, indemnify and hold harmless EVECS, LLC and its members, officers, employees and agents from any claim, damage, loss, liability, cost or expense (including reasonable legal fees) arising out of or related to your use of the Site, your breach of these Terms or of any law, your use of anything obtained from the Site, or any decision you or anyone relying on you made in reliance on it. We may take over the defence of any matter subject to this indemnity at your expense, and you will cooperate with us if we do.
We may suspend, restrict or withdraw your access to the Site at any time, with or without notice, if we believe your use breaches these Terms, threatens the Site or its availability, or exposes us or anyone else to legal risk. We may also change or discontinue the Site in whole or in part at any time. The Site is free, so no refund arises in any case. Sections that by their nature should survive, including sections 3, 4, 8 through 12 and 15, survive the end of your access.
We may update these Terms as the Site changes. When we do, we revise the last-modified date at the top, and the effective date when the substance changes. Except where the law requires otherwise, a change takes effect when it is posted, and continuing to use the Site after that means you accept it. If you do not accept a change, stop using the Site. Prior versions are not archived here; if you need to know what these Terms said on a particular date, ask us.
These Terms are governed by the laws of the State of Florida, excluding its conflict-of-laws rules. Subject to any consumer protection that cannot be waived where you live, the exclusive venue for any dispute arising out of or relating to these Terms or the Site is the state or federal courts located in the State of Florida, and you and we each consent to personal jurisdiction there.
Talk to us first. Before filing anything, send a short description of the dispute to contact@exploit.cc. If it is not resolved within 30 days, either of us may proceed. This costs you nothing and resolves most things faster than the alternative.
TO THE EXTENT PERMITTED BY LAW, YOU AND EVECS, LLC EACH AGREE TO BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE OR REPRESENTATIVE PROCEEDING.
Nothing here prevents either of us from seeking injunctive relief for infringement of intellectual property or unauthorised access to systems. If you are a consumer in a jurisdiction that restricts venue or waiver clauses, those clauses apply only as far as that law allows.
Questions about these Terms, and legal notices:
These Terms set out the rules for using a free public reference and allocate the risk of doing so. They are not legal advice to you.