Data sources
These are the data sources we rely on to provide accurate, up-to-date vulnerability and security intelligence.We thank these organizations for their valuable work and for making this information available to the community. All data is used in accordance with the respective source's license.
Vulnerability advisory providers
- • CVE.org – CVE Program (MITRE) - CVE Program Terms of Use
- • OSV.dev – Open Source Vulnerabilities - Per-source (varies)
- • GitHub Security Advisory Database - CC-BY-4.0
- • Red Hat Security Advisories - CC-BY-4.0
- • Arch Linux Security Tracker - MIT
- • GitLab Advisory Database - MIT
- • NIST NVD – National Vulnerability Database - Public domain
Severity and exploitation intelligence
- • VulnCheck – Vulnerability search and analysis - Attribution Notice
- • ENISA – European Union Agency for Cybersecurity - Legal Notice
- • CIRCL – Computer Incident Response Center Luxembourg - Per-source (varies)
- • EPSS – Exploit Prediction Scoring System - Usage terms
- • CISA KEV – Known Exploited Vulnerabilities Catalog - CC0-1.0
- • Exploit-DB – The Exploit Database (Offensive Security) - GPL-2.0-or-later
- • Nuclei Templates – ProjectDiscovery CVE Templates - MIT
- • PoC-in-GitHub – Public Proof-of-Concept Exploit Aggregator - No license stated
- • Metasploit Framework – Rapid7 Exploit Framework - BSD-3-Clause
- • GCVE – Global CVE Database - Per-source (varies)