Faults · NVD and CISA, read through this site’s relay
New software faults,
and the ones under attack.
Hundreds of newly published vulnerabilities enter the U.S. National Vulnerability Database on a working day, each under a CVE number. A much shorter list, kept by CISA, names the ones known to be exploited, each with the date it was added and the date by which federal agencies must have dealt with it. This desk reads both and sets them side by side: what was published or changed today and this week, how severe it is scored and by whom, whose product it is, and whether it is on CISA’s list.
It is a reference desk for people who patch things. It carries descriptions, scores and dates as their sources wrote them, and links to the NVD and CISA records. It carries no exploit code, no proof-of-concept links and no instructions: the reference lists that hold such links never leave the relay, and nothing a record says is ever turned into a link.
NVD’s CVE API 2.0 and CISA’s Known Exploited Vulnerabilities file · every list carries the time it was read · days are UTC days · This product uses data from the NVD API but is not endorsed or certified by the NVD.
New and changed
What NVD published, and what it changed.
Published means added to the NVD on that UTC day. Changed means an older record whose last-modified time falls on that day: a score arrived, a status moved, the author revised the text. The severity is the CVSS base score the record carries, with its version and whose score it is: NVD’s own where NVD has analysed the record, otherwise one supplied with the record by its numbering authority or by CISA’s enrichment. Where a record carries several, the row shows NVD’s own first, then the one NVD marks Primary, then the newest CVSS version; the opened record lists them all. A record nobody has scored says so.
NVD · published today
not read yet
Searches what these lists hold of each record: its id, NVD’s status, the first 420 characters of the description, up to four vendor and product names and the weakness ids. The whole record is behind its id.
| UTC day | Records | Read from NVD | State |
|---|
Known to be exploited
CISA’s list, newest first.
The Known Exploited Vulnerabilities catalog is CISA’s own list of vulnerabilities it has evidence are being used in real attacks. Each entry has the date CISA added it and a due date: the day by which CISA’s binding directive (BOD 26-04 today, BOD 22-01 before it) requires federal civilian agencies to have remediated it or stopped using the product. For anyone else the due date is a measure of how seriously CISA takes the entry, not an obligation. Not being on the list does not mean a vulnerability is safe; it means CISA has not listed it.
CISA · the exploited catalog
not read yet
Look one up
A record by its id, or by whose product it is.
A CVE id opens the whole record: the full description, every score with its vector, the vendor and product names, the weakness ids, CISA’s entry if there is one, and FIRST’s EPSS estimate. A vendor or a product searches two places and says which is which: CISA’s catalog by its own vendor and product fields, and NVD by the words of each record’s description.
Lookup
waiting for an id, a vendor or a product
Written CVE-YEAR-NUMBER, the number four to seven digits. Enter opens it too. The id goes to this site’s relay, which asks NVD and FIRST for it.
Either box or both: letters, digits and . _ + - only, two to forty characters. Enter searches too.
In CISA’s exploited catalog
In NVD, by the words of each description
Method
Three sources, each with its time on it.
Nothing on this page is written by this site except the sentences around the data. Every identifier, date, score, description and name is its source’s, read at the time printed beside it. When a source is slow, refuses, or answers in a shape this desk does not know, the page says which of those happened and keeps the last copy it had, with that copy’s age. It never fills a gap with a sample.
NVD: the records
Source. The National Vulnerability Database of the U.S. National Institute of Standards and Technology, through its CVE API 2.0 at services.nvd.nist.gov. Asked for: the records published on a UTC day, the records last modified on a UTC day, one record by its CVE id, and NVD’s keyword search of descriptions.
How fresh. This site’s relay keeps today’s published list for 30 minutes and today’s changed list for 2 hours (NVD asks callers not to re-read changes more often); a past day for 6 and 12 hours; a looked-up record for 30 minutes; a search for 1 hour. A day is not a past day until it is over: a list read before its UTC day ended is dropped two minutes into the next day and read again (a published list read in the first hour of the next day is kept one hour, then read once more), and until then the page marks it “read before the day ended”, never “fresh”. The time printed with each list is when the relay read NVD; “Ask again” asks the relay, which answers from its copy while that is inside these times. Without a key, NVD allows an address five questions in thirty seconds, so the relay reads it one question at a time, 6.5 seconds apart, for every reader together: the first reader of a quiet hour waits for the week to arrive a day at a time, and one reader may put eight new lookups (records or searches the relay does not already hold) to NVD in five minutes.
Licence. NIST’s publications are in the public domain in the United States. NVD asks services that use its API to say this, and it is true: This product uses data from the NVD API but is not endorsed or certified by the NVD.
CISA: the exploited catalog
Source. The Known Exploited Vulnerabilities catalog of the U.S. Cybersecurity and Infrastructure Security Agency, read as the JSON file CISA publishes on www.cisa.gov. Carried: the CVE id, vendor and product, CISA’s name and short description, the date added, the due date, the required action, the ransomware note, the forensic-triage note and the weakness ids. The file’s notes field, which is a list of outside links, is not carried.
How fresh. The relay keeps the file for 30 minutes. The status line prints the catalog version and release time CISA wrote into the file, and when the relay read it.
Licence. CISA distributes the catalog under the Creative Commons CC0 1.0 dedication. Using it does not imply endorsement by CISA or the Department of Homeland Security, and none is claimed.
FIRST: the EPSS estimate
Source. The Exploit Prediction Scoring System, maintained by the EPSS Special Interest Group at FIRST with scores generated by Empirical Security, through FIRST’s API at api.first.org. Asked for one record at a time, only when a record is opened: FIRST describes the API as built for lookup, not bulk reading.
How fresh. EPSS scores are published once a day; the relay keeps each for 6 hours and the record prints the day FIRST dated the score. A record published in the last day or two usually has no score yet, and the page says that rather than showing a zero.
What it is. An estimate of the probability that a vulnerability will be exploited in the next 30 days, and the share of scored vulnerabilities at or below that score. It is a model’s estimate, not an observation, and FIRST asks that it be attributed: EPSS, FIRST.org.
What this page does not know
- Whether you are affected. It lists records. It does not know what you run, in which version, or how it is exposed.
- Anything NVD has not received. A CVE id that is reserved, or published by its numbering authority in the last hour, may not be in NVD yet; NVD answers that such an id has no record, and the page says so.
- NVD’s own score for a record NVD has not analysed. Many new records stand at Received, Awaiting Analysis or Deferred (NVD’s word for “not currently scheduled for enrichment”). For those the score shown is the one supplied with the record, marked as not NVD’s, or there is none.
- Exploitation CISA has not listed. The catalog holds what CISA has evidence for and has chosen to list. Absence from it is not evidence of safety.
- What changed. “Changed” is NVD’s last-modified time. It says a record moved on that day, not which field moved. NVD keeps one such time for a record, so a record changed on two days of the week is listed under the later day only.
- Products by inventory. The vendor and product search of NVD is NVD’s keyword search: every word must appear in the record’s description. A product a description does not name is not found. The catalog search reads CISA’s own vendor and product fields.
- The references. NVD keeps a list of links with each record: advisories, patches, trackers and, sometimes, exploit code. This desk carries the count and none of the links. They are one press away, on NVD’s own record. A description or a vendor name is its author’s text and can itself contain a web address; it is shown as text and is never a link here.
- A record it cannot read. If NVD sends a record this desk cannot read (an id outside CVE-YEAR-NUMBER with four to seven digits, or no dates), the record is left out, the day’s line says how many were, and the rest are shown.
- More than 10,000 records in one UTC day. The relay reads at most five pages of 2,000 for a day and the page says when a day ran past that.
What is asked, and of whom
- Your browser asks this site only. The lists come from a relay on labs.llc. NVD, CISA and FIRST see this server’s request, not yours: not your address, not your browser.
- What the relay passes on. A UTC date, a CVE id, or the vendor and product words you typed. Nothing else of a request reaches a source: the relay can ask three named hosts, each on one fixed path, and refuses any other question in words.
- What the relay keeps. The answers, cut down to what this page shows, for the times above and for up to 7 days (NVD), 14 days (CISA) or 3 days (EPSS) as a last copy to show, said to be old, when a source is down. To hold each reader to a fair share it counts requests for five minutes under a keyed hash of the network address; the relay itself writes no record of who asked what. A question is, like any web request, part of the address your browser asks this site for, and the hosting’s ordinary access log may record it.
- The address bar. Opening a record writes its CVE id after the # so the view can be linked. The site’s analytics may record the page address as it stands.
- A key, if the server has one. NVD issues free API keys that raise its limit. If this server is given one it stays on the server; the page says which way NVD is being read, here: not read yet.
Times are UTC unless they say otherwise. See also the data, and what it is not and privacy.