Sources

Every source the pages use, with its licence, the date we read its terms and what we take from it. Updated .

What we read

Every source the pages use, its licence or terms, when we last read those terms, and what we take from it.
SourceLicence or termsTerms readWhat we use
CISA Known Exploited Vulnerabilities catalogCC0 1.0 Universal1 October 2026Every entry: CVE id, vendor, product, name, description, required action, listing and due dates, ransomware use, forensic triage, notes and links. Read hourly from CISA's own copy on GitHub (cisagov/kev-data, same licence), whose history since January 2025 gives our change log.
EPSS, the Exploit Prediction Scoring System (FIRST)Free to use; FIRST asks for credit wherever the scores are shown1 October 2026The daily score and percentile of every CVE, and each day's file since 4 February 2022 for the lines on CVE pages and the score on the day CISA listed an entry.
CVE records (CVE Services, the CVE Program)CVE Program Terms of Use2 October 2026The record of every listed CVE and of the CVEs EPSS rates 0.50 or more: description, dates, assigner, affected products, CWE ids and CVSS.
CISA VulnrichmentCC0 1.0 Universal2 October 2026CISA's SSVC decision points inside the CVE records: exploitation, automatable and technical impact.
CWE, the Common Weakness Enumeration (MITRE)CWE Terms of Use2 October 2026The name of each weakness a CVE record or CISA's entry names.
Metasploit Framework module metadata (Rapid7)BSD 3-Clause2 October 2026Facts only: which modules name a CVE, their name, type and rank. Never code, and never a path to it.
Exploit-DB repository index (OffSec)GPL v2 for the repository2 October 2026Facts only, from the repository's index file: which entries name a CVE, their id, title, date and whether Exploit-DB verified them. Each entry links to its page on exploit-db.com; we read nothing from that site.

The credit lines we use

  • CISA Known Exploited Vulnerabilities catalog (CC0). Not affiliated with or endorsed by CISA.
  • EPSS scores by FIRST (https://www.first.org/epss/), generated by Empirical Security.
  • CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
  • CWE names: Copyright © 2006-2026, The MITRE Corporation. CWE, CWSS, CWRAF, and the CWE logo are trademarks of The MITRE Corporation.
  • Metasploit Framework module metadata: Copyright 2006-2026, Rapid7, Inc.

The CVE Program's licence

The CVE Program Terms of Use say: "MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy."

The CWE licence

The CWE Terms of Use say: "CWE is free to use by any organization or individual for any research, development, and/or commercial purposes, per these CWE Terms of Use. Accordingly, The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. Any copy you make for such purposes is authorized on the condition that you reproduce MITRE's copyright designation and this license in any such copy."

CISA's licence

CISA publishes its list under CC0 1.0 and says that using it "does not authorize you to use the CISA Logo or DHS Seal, nor should such use be interpreted as an endorsement by CISA or DHS." This site shows neither and claims no endorsement.

What we do not use

No vendor's advisory text: we link each advisory CISA names, but quote none. Microsoft's update guide is not a source here, because its terms allow only personal, non-commercial use; Microsoft's CVE records reach us through the CVE Program like every other.