Data Sources & Attribution

This application aggregates CVE vulnerability data from multiple authoritative sources. Each source is listed below with the terms we rely on to use its data, and with the credit those terms ask us to give.

Required Notices

Some of the sources we use require a specific notice wherever their data appears. Those notices are reproduced here in full.

NVD — National Vulnerability Database (NIST)

“This product uses the NVD API but is not endorsed or certified by the NVD.”

NIST does not endorse this product. Our use of NVD data does not imply any endorsement, certification, or affiliation by NIST or the NVD. Where we combine NVD data with other sources or reformat it, the result is ours and is not attributed to the NVD.

GitHub Security Advisories (GHSA)

Advisory data from the GitHub Advisory Database, © GitHub, Inc., used under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).

We merge this data with other sources and reformat it for display. Those changes are ours. GitHub does not endorse this product or our presentation of its data.

https://creativecommons.org/licenses/by/4.0/

Red Hat Security Data

Security advisory data from Red Hat, Inc., used under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). We reformat and combine it with other sources; those changes are ours and are not endorsed by Red Hat.

CVE Program (The MITRE Corporation)

CVE® Records are used under the CVE Program Terms of Use, which grant a royalty-free licence to reproduce and redistribute CVE on condition that MITRE's copyright designation is reproduced with it: © The MITRE Corporation.

CVE is a registered trademark of The MITRE Corporation.

NVD

National Vulnerability Database (NVD)

Operated by NIST (National Institute of Standards and Technology)

The NVD is the U.S. government repository of standards-based vulnerability management data. NVD content is a work of the U.S. government and is in the public domain, but access to the NVD API carries its own terms of use. This product uses the NVD API but is not endorsed or certified by the NVD. NIST does not endorse this product, and our use of NVD data does not imply any endorsement, certification, or affiliation by NIST or the NVD.

https://nvd.nist.gov/developers/terms-of-use
CVE

MITRE CVE Program

The CVE Program is sponsored by CISA

The CVE Program identifies, defines, and catalogs publicly disclosed cybersecurity vulnerabilities. CVE Records are provided by MITRE under the CVE Program Terms of Use — a royalty-free licence to reproduce and redistribute CVE, on condition that MITRE's copyright designation is reproduced with it. © The MITRE Corporation.

https://www.cve.org/Legal/TermsOfUse
RH

Red Hat Security Data

Red Hat, Inc.

Red Hat security advisories and CVE data. Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). We reformat this data and combine it with other sources; those changes are ours.

https://access.redhat.com/security/data
GH

GitHub Security Advisories (GitHub Advisory Database)

GitHub, Inc.

Security advisories from the GitHub Advisory Database, a free and open-source repository of security advisories. Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0), which requires attribution to GitHub Security Advisories and a link to the licence. We merge and reformat this data; those changes are ours, not GitHub's.

https://github.com/advisories https://creativecommons.org/licenses/by/4.0/
CL

CIRCL Vulnerability-Lookup

Computer Incident Response Center Luxembourg

Vulnerability correlation and lookup service operated by CIRCL, co-funded by the European Union. CIRCL is an aggregator: it does not publish a single licence covering the combined feed, and each record stays under the terms of whichever upstream source it came from. The Vulnerability-Lookup software itself is AGPL-3.0.

https://vulnerability.circl.lu/
.org

CVE.org Disabled

CVE Program — operated by the CVE Board

The official CVE record lookup service. Records are used under the same CVE Program Terms of Use as above: a royalty-free licence to redistribute CVE, provided MITRE's copyright designation is reproduced with it. © The MITRE Corporation.

https://www.cve.org/
CD

CVE Details Disabled

SecurityScorecard

CVE security vulnerability database with detailed scoring, affected products, and exploit information. This is a commercial service and requires an API key. Its data terms are set by the subscriber agreement rather than a public licence, so we make no public licence claim for it here.

https://www.cvedetails.com/
KEV

CISA Known Exploited Vulnerabilities (KEV)

Cybersecurity and Infrastructure Security Agency (CISA)

The authoritative catalog of vulnerabilities that have been exploited in the wild. As a work of the U.S. government, CISA KEV data is in the public domain, and CISA's own KEV data repository is published under CC0 1.0. No attribution is required, and CISA does not endorse this product.

https://www.cisa.gov/known-exploited-vulnerabilities-catalog
EDB

ExploitDB

OffSec (Offensive Security)

Archive of public exploits and corresponding vulnerable software. The Exploit Database repository is published by OffSec under the GNU General Public License v2.0. We read only its CVE-to-exploit index to flag CVEs with known public exploits — we do not redistribute exploit code.

https://www.exploit-db.com/
EPSS

EPSS (Exploit Prediction Scoring System)

FIRST (Forum of Incident Response and Security Teams)

Daily probability estimates that a vulnerability will be exploited in the next 30 days. FIRST publishes EPSS scores freely and asks users to provide attribution where possible, which is what this entry is. The model is cited as Jacobs et al. (2021), “Exploit Prediction Scoring System (EPSS)”, Digital Threats: Research and Practice 2(3).

https://www.first.org/epss/
EU

EUVDB (European Vulnerability Database) Disabled

ENISA (European Union Agency for Cybersecurity)

The EU vulnerability database established under the NIS2 Directive, providing CVSS scoring, EPSS probability, and exploitation status for vulnerabilities affecting EU products and services. We have not been able to verify published licence terms for the EUVD API, so we make no licence claim for it here.

https://euvd.enisa.europa.eu/

Software used for SBOM scanning

When you upload or link a software bill of materials, we match its components against these additional datasets. They are shipped or fetched by us rather than queried as a live CVE feed.

GRY

Anchore Grype vulnerability database

Anchore, Inc.

We run the open-source Grype scanner against SBOMs, using the vulnerability database Anchore publishes for it. The Grype scanner and the pipeline that builds the database are licensed under the Apache License 2.0. The contents of the hosted database itself carry no published licence or terms of use. We state that plainly rather than claim terms that have not been granted, and Anchore does not endorse this product.

https://github.com/anchore/grype
JAR

trivy-java-db

Aqua Security

An index mapping JAR checksums to Maven coordinates, published by Aqua Security and redistributed by us under the Apache License 2.0. It contains no vulnerability data of its own — we use it to identify Java components correctly before matching them against the advisory sources above. Aqua Security does not endorse this product.

https://github.com/aquasecurity/trivy-java-db

Disclaimer

This application aggregates publicly available CVE data from the sources listed above. We do not guarantee the accuracy, completeness, or timeliness of this data. Always refer to the original sources for authoritative information.

Listing a source here credits it as required by its terms. It is not a claim of partnership, sponsorship, certification, or endorsement by any of the organisations named, and none of them endorse this product.

Where we state that a source's terms are unpublished or unverified, that is deliberate: we would rather say so than claim a licence we have not been granted. If you believe an entry on this page is wrong or incomplete, please tell us and we will correct it.

CVE is a registered trademark of The MITRE Corporation.

Source terms last reviewed: 17 August 2026.