exploit_type Improved Coverage - Grew exploits index exploit_type field coverage from 10% to 90% over the past two sprintsMicrosoft end of life notices are product status updates found on Microsoft's notice pages indicating when specific hardware and software products have reached or are approaching end of sale, end of support, or end of life status. These pages provide information about discontinuation timelines, helping organizations plan equipment refresh cycles and maintain operational continuity.
Browse the microsoft-eol index
Alibaba Cloud end of life notices are product status updates found on Alibaba Cloud's notice pages indicating when specific software products have reached or are approaching end of sale, end of support, or end of life status. These pages provide information about discontinuation timelines, helping organizations plan equipment refresh cycles and maintain operational continuity.
Browse the alibabacloud-eol index
Maven (Java) packages with package versions
This index serves as a unified cross-reference between CVE IDs and their equivalent identifiers in other vulnerability databases. It is a growing cross-reference that maps CVE IDs to their equivalent identifiers across the broader vulnerability ecosystem — from regional and governmental databases (JVNDB, EUVD) to platform-specific advisory systems (GHSA) and beyond. As more sources are onboarded, the index expands to cover an increasingly complete picture of how a single vulnerability is tracked across the world.
[Browse the cves_identity_mappings index](https://console.vulncheck.com/api/?index=cves_identity_mappings To Various IDs Mapping){:target="_blank"}
Independent security research practice operated in Copenhagen, Denmark, publishing vulnerability advisories. Advisories are published in CVE JSON 5.1 format and registered as a GNA in the GCVE system
German offensive security firm founded in 2018, specialising in penetration testing, security assessments, and code reviews. Their "Bug Parade" advisory feed publishes original vulnerability research discovered during engagements and internal research, covering web applications, networks, and cloud environments. Registered as a GNA, publishing advisories in CVE JSON v5 format.
A collective of independent security researchers and hackers based in Austin, Texas, and one of the first hacker groups to become a CVE Numbering Authority and GCVE Numbering Authority. Founded and led by Tod Beardsley (former CISA Vulnerability Response Section Chief and CVE Board member), AHA! publishes original vulnerability research covering a broad range of software and systems under both CVE and native GCVE identifiers.
Browse the austin-hackers index
Draeger Security Advisories are official notifications released by Draeger to address security vulnerabilities and updates in their cloud services and infrastructure. These bulletins provide important information about the vulnerabilities, their potential impact, and recommendations for users to apply necessary patches or configuration changes to ensure the security of their systems.
AWS Relational Database Bulletins are official notifications released by Amazon Web Services to address security vulnerabilities and updates in their cloud services and infrastructure. These bulletins provide important information about the vulnerabilities and version configurations for users to apply necessary patches or configuration changes to ensure the security of their systems.
Governing body behind OPC UA — the dominant interoperability standard for industrial automation and critical infrastructure. Advisories cover vulnerabilities in OPC UA implementations across 600+ member companies including Siemens, Honeywell, and Rockwell.
Browse the opc-foundation index
The Computer Incident Response Center Luxembourg (CIRCL) is a government-driven initiative designed to gather, review, report and respond to computer security threats and incidents.
The VulnCheck IOC Threat Actors index contains curated indicators of compromise associated with known advanced persistent threat (APT) groups and known threat actors. Threat actors are individuals or organized groups who deliberately conduct malicious cyber operations — often with geopolitical, financial, or espionage motivations — targeting governments, critical infrastructure, and enterprises.
Browse the ioc-threat-actors index
The VulnCheck IOC Ransomware index contains curated indicators of compromise associated with named ransomware groups and their campaigns. Ransomware is a category of malware used by criminal organizations to encrypt victim data or systems and extort payment in exchange for restoration of access.
Browse the ioc.ransomware index
The VulnCheck IOC Botnets index contains curated indicators of compromise associated with known botnet families. A botnet is a network of compromised devices under the control of a threat actor, commonly used to conduct distributed denial-of-service attacks, deliver malware, exfiltrate data, or perform large-scale fraud.
Anthropic Red CVD is a disclosure-ledger feed from Anthropic’s Frontier Red Team. It tracks validated findings using sealed-report hashes, disclosure statuses, commitment dates, and, when revealed, identifiers, projects, and bug classes. The feed helps users monitor which findings are pre-disclosure, disclosed, or fixed over time. It is useful for researchers, analysts, and teams tracking AI safety and vulnerability disclosure signals.