Sources
Every source the pages use, with its licence, the date we read its terms and what we take from it. Updated .
What we read
| Source | Licence or terms | Terms read | What we use |
|---|---|---|---|
| CISA Known Exploited Vulnerabilities catalog | CC0 1.0 Universal | 1 October 2026 | Every entry: CVE id, vendor, product, name, description, required action, listing and due dates, ransomware use, forensic triage, notes and links. Read hourly from CISA's own copy on GitHub (cisagov/kev-data, same licence), whose history since January 2025 gives our change log. |
| EPSS, the Exploit Prediction Scoring System (FIRST) | Free to use; FIRST asks for credit wherever the scores are shown | 1 October 2026 | The daily score and percentile of every CVE, and each day's file since 4 February 2022 for the lines on CVE pages and the score on the day CISA listed an entry. |
| CVE records (CVE Services, the CVE Program) | CVE Program Terms of Use | 2 October 2026 | The record of every listed CVE and of the CVEs EPSS rates 0.50 or more: description, dates, assigner, affected products, CWE ids and CVSS. |
| CISA Vulnrichment | CC0 1.0 Universal | 2 October 2026 | CISA's SSVC decision points inside the CVE records: exploitation, automatable and technical impact. |
| CWE, the Common Weakness Enumeration (MITRE) | CWE Terms of Use | 2 October 2026 | The name of each weakness a CVE record or CISA's entry names. |
| Metasploit Framework module metadata (Rapid7) | BSD 3-Clause | 2 October 2026 | Facts only: which modules name a CVE, their name, type and rank. Never code, and never a path to it. |
| Exploit-DB repository index (OffSec) | GPL v2 for the repository | 2 October 2026 | Facts only, from the repository's index file: which entries name a CVE, their id, title, date and whether Exploit-DB verified them. Each entry links to its page on exploit-db.com; we read nothing from that site. |
The credit lines we use
- CISA Known Exploited Vulnerabilities catalog (CC0). Not affiliated with or endorsed by CISA.
- EPSS scores by FIRST (https://www.first.org/epss/), generated by Empirical Security.
- CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
- CWE names: Copyright © 2006-2026, The MITRE Corporation. CWE, CWSS, CWRAF, and the CWE logo are trademarks of The MITRE Corporation.
- Metasploit Framework module metadata: Copyright 2006-2026, Rapid7, Inc.
The CVE Program's licence
The CVE Program Terms of Use say: "MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy."
- CVE Program Terms of Usecve.org
The CWE licence
The CWE Terms of Use say: "CWE is free to use by any organization or individual for any research, development, and/or commercial purposes, per these CWE Terms of Use. Accordingly, The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. Any copy you make for such purposes is authorized on the condition that you reproduce MITRE's copyright designation and this license in any such copy."
- CWE Terms of Usecwe.mitre.org
CISA's licence
CISA publishes its list under CC0 1.0 and says that using it "does not authorize you to use the CISA Logo or DHS Seal, nor should such use be interpreted as an endorsement by CISA or DHS." This site shows neither and claims no endorsement.
What we do not use
No vendor's advisory text: we link each advisory CISA names, but quote none. Microsoft's update guide is not a source here, because its terms allow only personal, non-commercial use; Microsoft's CVE records reach us through the CVE Program like every other.