Skip to content

Authoritative Vulnerability Intelligence

Vulnerability Authorities

The challenge: Vulnerability data is fragmented across dozens of disconnected databases, each with different formats, identifiers, and update cadences. Correlating a single vulnerability across NVD, GHSA, and OSV means querying three APIs and reconciling the results yourself.
What you get: One API query returns normalised, enriched records from every major vulnerability authority worldwide. Cross-referenced identifiers, unified severity scoring, and a single source of truth.
SourcePrefixDescription
MITRE CVECVE-The global standard for vulnerability identification. Official CVE Records in CVE JSON 5.0 format from the MITRE Corporation.
NIST NVDCVE-US National Vulnerability Database. CVSS scoring, CPE matching, and CWE classification for published CVEs.
NIST NVD RecentCVE-Recently published and modified NVD entries, polled at higher frequency for faster ingestion.
NIST NVD (OSV)CVE-NVD data surfaced through the OSV ecosystem for package-level correlation.
VulnCheck NVDCVE-VulnCheck's enhanced NVD mirror with faster update cadence and additional enrichment.
GHSAGHSA-GitHub Security Advisories. Ecosystem-specific advisories with affected version ranges for open source packages.
GHSA (OSV)GHSA-GitHub Security Advisories surfaced through the OSV schema.
EUVDEUVD-European Union Vulnerability Database. EU-wide vulnerability coordination under the NIS2 directive.
CISA KEVCVE-CISA Known Exploited Vulnerabilities catalog. Confirmed actively exploited vulnerabilities with remediation deadlines.
VulnCheck KEVCVE-VulnCheck's expanded KEV dataset with additional exploitation evidence beyond the CISA catalog.
ENISA EU KEVCVE-ENISA's European Known Exploited Vulnerabilities list. EU-specific exploitation intelligence.
CISA ADP VulnrichmentCVE-CISA Authorized Data Publisher enrichment. SSVC scores, stakeholder context, and supplemental analysis.
Anchore ADPCVE-Anchore's Authorized Data Publisher feed. Container and supply chain vulnerability enrichment.
CNVD AdvisoryCNVD-China National Vulnerability Database. Chinese-language vulnerability advisories and coordination.
FSTEC BDUBDU:Russian Federal Service for Technical and Export Control. Russian vulnerability database and advisories.
VARIoTVAR-Vulnerability and Attack Repository for IoT. IoT-specific vulnerability intelligence.
Open Cloud Vulnerability DBCloud-native vulnerability intelligence for AWS, Azure, and GCP services.
Google Open Source IntelligenceGoogle's open source vulnerability intelligence programme and research disclosures.
circlComputer Incident Response Center Luxembourg. European vulnerability coordination and intelligence sharing.
Coalition ESSCoalition Exploit Scoring System. Exploit availability and usage probability scores for risk prioritisation.
Wiz Vulnerability DatabaseWiz cloud security vulnerability intelligence with cloud-specific context and remediation guidance.
Veracode SourceClearVeracode SourceClear Vulnerability Database. Commercial SCA vulnerability data with method-level analysis.
SnykSNYK-Snyk vulnerability database. Commercial vulnerability intelligence with remediation advice and fix PRs.

See the Licensing Appendix for redistribution terms applicable to each source.