Third-party notices and data licenses
Where every number on this site comes from, what license it arrives under, and what that license lets anyone do with it.
How to read this
Each entry says what EVULNABLE takes from that source, the license it comes under, and what the license permits. Where a license requires its notice be reproduced word for word, the notice is printed in full rather than summarized.
A few entries are marked Under review. That means the redistribution rights are an open question being settled, not that anything is known to be wrong. Where EVULNABLE is unsure what a license permits, it says so here rather than leaving the reader to assume.
Data sources
- Used for
- Known-exploitation status, ransomware association, required actions and federal remediation due dates.
- License
- CC0 1.0 Universal (public domain dedication)
- What it permits
- Dedicated to the public domain. No permission or attribution is required. EVULNABLE attributes it anyway, because a reader deciding whether to trust a number needs to know where it came from.
- Used for
- Exploitation probability and percentile.
- License
- Free use under FIRST's open data terms, with attribution
- What it permits
- Free to use, including commercially, provided FIRST is credited as the source. The credit appears in the footer of every page that shows an EPSS value and in each generated report.
- Used for
- CVE search, and CVSS vectors for KEV entries CISA's own schema does not carry.
- License
- US Government work — not subject to copyright in the United States
- What it permits
- Freely usable with attribution. NIST does not endorse any product or service, and its data is provided without warranty; EVULNABLE's use of it implies no NIST endorsement of EVULNABLE.
- Used for
- Microsoft product lifecycle milestones — end of support, end of servicing and extended-support dates.
- License
- MIT License
- What it permits
- Permissive: use, copy, modify, publish and distribute, including commercially, provided the copyright and permission notice below travel with it. That notice is why this page exists.
Required license notice, in full
Copyright (c) endoflife.date contributors
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
- Used for
- The monthly Patch Tuesday CVE list — titles, MSRC severity, CVSS, exploitability signals, disclosure status and KB article numbers.
- License
- No license stated at the endpoint; Microsoft's general API Terms may or may not apply
- What it permits
- Consumed from Microsoft's public CVRF endpoint, which requires no key and no acceptance step. Microsoft's general API Terms restrict redistributing, reselling and sublicensing API data; whether those generic terms govern this specific endpoint has not been established either way, and is being reviewed before any commercial offering. Nothing here asserts that the current free, attributed, per-entry-linked use is or is not permitted.
- Used for
- Fixed versions, vendor-required actions and remediation guidance per CVE.
- License
- No published data-use terms; fair-use polling guidance only
- What it permits
- Accessed through the project's public MCP endpoint and data shards, which need no key. EVULNABLE honours the published fair-use guidance — cache headers respected and sustained polling held at or under one request per second, enforced in code rather than intended — and carries each value's own upstream attribution through to the page. The republication and commercial-reuse rights are being put in writing.
- Used for
- Per-CVE threat research coverage.
- License
- Headline, date and link only
- What it permits
- EVULNABLE stores and shows the title, the publication date and a link to Check Point's own write-up. No article text is copied, and every reference sends the reader to the original.
- Used for
- Red Hat, Ubuntu and Debian security advisories.
- License
- Per-distribution terms
- What it permits
- Advisory metadata and links only, each entry pointing at the distribution's own advisory. Individual terms are reviewed per source before any commercial redistribution.
- Used for
- Adobe, Apple, Google Chrome, Cisco, Ivanti and Oracle advisories.
- License
- Metadata and links only
- What it permits
- EVULNABLE lists each bulletin's title, date and identifiers and links to the vendor's own page. Where a vendor's bulletin does not name a CVE, the entry says “Not listed” rather than inventing one. Cisco PSIRT is read through its openVuln API, whose terms attach to the API key.
- Used for
- Resolving domains for the Public DNS Checker.
- License
- Public resolver
- What it permits
- Used as a resolver only. No Cloudflare content is stored or republished.
Software and typefaces
- Used for
- The typeface on every page and in every generated PDF.
- License
- SIL Open Font License 1.1
- What it permits
- Licensed under the SIL Open Font License 1.1. The fonts may be used, studied, modified and redistributed freely so long as they are not sold on their own; the full license text ships beside the font files.
- Used for
- CVE identifiers, KB numbers, hostnames and IP addresses — anything a reader might copy.
- License
- SIL Open Font License 1.1
- What it permits
- Licensed under the SIL Open Font License 1.1. The fonts may be used, studied, modified and redistributed freely so long as they are not sold on their own; the full license text ships beside the font files.
What EVULNABLE adds
The facts above are not EVULNABLE's to license — a CVE identifier, a CISA KEV listing and an EPSS probability belong to the bodies that publish them, and this site passes them through with attribution.
What EVULNABLE creates on top of them is the EVULNABLE Risk Score, its band vocabulary, the written summaries and comparisons, and the generated reports. Terms covering the reuse of those are being written. Until they are published, treat EVULNABLE-created content as all rights reserved and ask — the answer is likely to be yes, and it is better recorded than assumed.
Something wrong here?
If you maintain one of these sources and EVULNABLE has mischaracterized your license, credited you incorrectly, or is using your data in a way you did not intend, say so and it will be corrected or the use stopped. That is a faster route than a legal one and it is the one this project would rather you take.