Third-party notices and data licenses

Where every number on this site comes from, what license it arrives under, and what that license lets anyone do with it.

How to read this

Each entry says what EVULNABLE takes from that source, the license it comes under, and what the license permits. Where a license requires its notice be reproduced word for word, the notice is printed in full rather than summarized.

A few entries are marked Under review. That means the redistribution rights are an open question being settled, not that anything is known to be wrong. Where EVULNABLE is unsure what a license permits, it says so here rather than leaving the reader to assume.

Data sources

CISA Known Exploited Vulnerabilities Catalog

Used for
Known-exploitation status, ransomware association, required actions and federal remediation due dates.
License
CC0 1.0 Universal (public domain dedication)
What it permits
Dedicated to the public domain. No permission or attribution is required. EVULNABLE attributes it anyway, because a reader deciding whether to trust a number needs to know where it came from.

FIRST EPSS (Exploit Prediction Scoring System)

Used for
Exploitation probability and percentile.
License
Free use under FIRST's open data terms, with attribution
What it permits
Free to use, including commercially, provided FIRST is credited as the source. The credit appears in the footer of every page that shows an EPSS value and in each generated report.

NIST National Vulnerability Database (NVD)

Used for
CVE search, and CVSS vectors for KEV entries CISA's own schema does not carry.
License
US Government work — not subject to copyright in the United States
What it permits
Freely usable with attribution. NIST does not endorse any product or service, and its data is provided without warranty; EVULNABLE's use of it implies no NIST endorsement of EVULNABLE.

endoflife.date

Used for
Microsoft product lifecycle milestones — end of support, end of servicing and extended-support dates.
License
MIT License
What it permits
Permissive: use, copy, modify, publish and distribute, including commercially, provided the copyright and permission notice below travel with it. That notice is why this page exists.
Required license notice, in full
Copyright (c) endoflife.date contributors Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Microsoft Security Update Guide (CVRF v3.0) Under review

Used for
The monthly Patch Tuesday CVE list — titles, MSRC severity, CVSS, exploitability signals, disclosure status and KB article numbers.
License
No license stated at the endpoint; Microsoft's general API Terms may or may not apply
What it permits
Consumed from Microsoft's public CVRF endpoint, which requires no key and no acceptance step. Microsoft's general API Terms restrict redistributing, reselling and sublicensing API data; whether those generic terms govern this specific endpoint has not been established either way, and is being reviewed before any commercial offering. Nothing here asserts that the current free, attributed, per-entry-linked use is or is not permitted.

CyberSecurityTracker.ai Under review

Used for
Fixed versions, vendor-required actions and remediation guidance per CVE.
License
No published data-use terms; fair-use polling guidance only
What it permits
Accessed through the project's public MCP endpoint and data shards, which need no key. EVULNABLE honours the published fair-use guidance — cache headers respected and sustained polling held at or under one request per second, enforced in code rather than intended — and carries each value's own upstream attribution through to the page. The republication and commercial-reuse rights are being put in writing.

Check Point Research

Used for
Per-CVE threat research coverage.
License
Headline, date and link only
What it permits
EVULNABLE stores and shows the title, the publication date and a link to Check Point's own write-up. No article text is copied, and every reference sends the reader to the original.

Linux distribution security feeds Under review

Used for
Red Hat, Ubuntu and Debian security advisories.
License
Per-distribution terms
What it permits
Advisory metadata and links only, each entry pointing at the distribution's own advisory. Individual terms are reviewed per source before any commercial redistribution.

Vendor security bulletins

Used for
Adobe, Apple, Google Chrome, Cisco, Ivanti and Oracle advisories.
License
Metadata and links only
What it permits
EVULNABLE lists each bulletin's title, date and identifiers and links to the vendor's own page. Where a vendor's bulletin does not name a CVE, the entry says “Not listed” rather than inventing one. Cisco PSIRT is read through its openVuln API, whose terms attach to the API key.

Cloudflare DNS over HTTPS

Used for
Resolving domains for the Public DNS Checker.
License
Public resolver
What it permits
Used as a resolver only. No Cloudflare content is stored or republished.

Software and typefaces

Instrument Sans

Used for
The typeface on every page and in every generated PDF.
License
SIL Open Font License 1.1
What it permits
Licensed under the SIL Open Font License 1.1. The fonts may be used, studied, modified and redistributed freely so long as they are not sold on their own; the full license text ships beside the font files.

IBM Plex Mono

Used for
CVE identifiers, KB numbers, hostnames and IP addresses — anything a reader might copy.
License
SIL Open Font License 1.1
What it permits
Licensed under the SIL Open Font License 1.1. The fonts may be used, studied, modified and redistributed freely so long as they are not sold on their own; the full license text ships beside the font files.

What EVULNABLE adds

The facts above are not EVULNABLE's to license — a CVE identifier, a CISA KEV listing and an EPSS probability belong to the bodies that publish them, and this site passes them through with attribution.

What EVULNABLE creates on top of them is the EVULNABLE Risk Score, its band vocabulary, the written summaries and comparisons, and the generated reports. Terms covering the reuse of those are being written. Until they are published, treat EVULNABLE-created content as all rights reserved and ask — the answer is likely to be yes, and it is better recorded than assumed.

Something wrong here?

If you maintain one of these sources and EVULNABLE has mischaracterized your license, credited you incorrectly, or is using your data in a way you did not intend, say so and it will be corrected or the use stopped. That is a faster route than a legal one and it is the one this project would rather you take.