Usually not. Typically, when you don’t see exploit code on exploit-db for a vulnerability, it was responsibly disclosed to a vendor and patched privately. A CVE will still be issued for the vulnerability and knowledge, but the exploit code would never be published, at least not in its entirety.