Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.
-
Updated
Sep 14, 2026 - Python
Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.
Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits and advisories (CVSS/EPSS/KEV), audit software, Linux/Windows hosts and SBOMs, and stream the whole graph. Typed sync + async clients, 100% v3-compatible, with a built-in MCP server for AI agents.
PoC_CVEs
Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.
This repository is a curated resource for aspiring bug hunters, offering hands-on labs, tools, and structured guidance to support your learning and practical development in the field of ethical hacking and vulnerability research.
This repo contains a dump of mappings of NVD's CPEs to purls (package URLs) derived from the VulnerableCode database. package urls created by using VulnerableCode's data. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/discuss
Hecate Cyber Defense - AI-powered vulnerability analysis
Vulnerability intelligence API aggregating NVD, OSV, CVE Records (CNA), CISA KEV, and EPSS, plus PSIRT advisories from network appliance vendors (Cisco, Fortinet, Palo Alto Networks, and more) into one searchable REST API. Self-hosted; TypeScript, Fastify, Prisma, PostgreSQL.
Public registry for AI code failures. AICI identifiers. Detection rule mapping. Vendor notification.
MCP-сервер для БДУ ФСТЭК (86 000+ российских уязвимостей). Поиск через SQLite FTS5 с фильтрами по CVSS/опасности/году/вендору, обратный маппинг CVE→БДУ. Обход геоблока через GitHub-зеркало.
Неофициальное зеркало БДУ ФСТЭК без геоблока: XML + XLSX + готовая SQLite-база с FTS5-индексом. 86 000+ уязвимостей, доступно через raw.githubusercontent.com.
MCP server: 1,032 verified smart contract vulnerability findings from 10 Sherlock audit contests
Live database of TeamPCP supply chain attack compromises — LiteLLM, Telnyx, Trivy, and more. Includes CLI scanner and REST API.
Read-only reference API for AVE, the behavioral classification standard for agentic AI components. Not the standard itself, see aveproject/ave.
Current public ESIP exposure signal data feed for community and research use.
VulDB Ruby code to fetch data via API
Cybersecurity threat intelligence for AI agents — CVE search, EPSS exploit prediction, CISA KEV, IP reputation, threat feed. MCP + x402.
To associate your repository with the vulnerability-database topic, visit your repo's landing page and select "manage topics."