VulnCheck July 22nd Release Notes

  • AI / Agent-Ready CLI - Shipped agentic AI-ready CLI updates, letting users query VulnCheck data in natural language via Claude or any LLM. See the agentic usage guide.
  • Expanded V4 Advisory Support - Added V4 advisory support for Debian, Node.js, Siemens, Citrix, Dell, Zoom, NCSC-CVEs, and 7-Zip, with more indexes coming soon
  • Exploits Index exploit_type Improved Coverage - Grew exploits index exploit_type field coverage from 10% to 90% over the past two sprints
  • Improved Maven (Java) Package Intelligence - Overhauled the Maven package pipeline end-to-end, boosting data coverage, freshness, resilience, and efficiency
  • CVE Prioritization & Community Data Technical Guide - Published a technical guide with plug-and-play code for extracting prioritization signals from CVE scanner results using VulnCheck Community data. See the Community how-to guides.
  • Production API Service Level Objectives (SLOs) - Continued refining production API SLOs to support world-class availability and reliability

New Indices Added

Microsoft End of Life Notices

Microsoft end of life notices are product status updates found on Microsoft's notice pages indicating when specific hardware and software products have reached or are approaching end of sale, end of support, or end of life status. These pages provide information about discontinuation timelines, helping organizations plan equipment refresh cycles and maintain operational continuity.

Browse the microsoft-eol index

Alibaba Cloud End of Life Notices

Alibaba Cloud end of life notices are product status updates found on Alibaba Cloud's notice pages indicating when specific software products have reached or are approaching end of sale, end of support, or end of life status. These pages provide information about discontinuation timelines, helping organizations plan equipment refresh cycles and maintain operational continuity.

Browse the alibabacloud-eol index

Maven-CS

Maven (Java) packages with package versions

Browse the maven-cs index

CVE To Various IDs Mapping. This index holds cves to different ids mappings

This index serves as a unified cross-reference between CVE IDs and their equivalent identifiers in other vulnerability databases. It is a growing cross-reference that maps CVE IDs to their equivalent identifiers across the broader vulnerability ecosystem — from regional and governmental databases (JVNDB, EUVD) to platform-specific advisory systems (GHSA) and beyond. As more sources are onboarded, the index expands to cover an increasingly complete picture of how a single vulnerability is tracked across the world.

[Browse the cves_identity_mappings index](https://console.vulncheck.com/api/?index=cves_identity_mappings To Various IDs Mapping){:target="_blank"}

Moksha Security Advisories

Independent security research practice operated in Copenhagen, Denmark, publishing vulnerability advisories. Advisories are published in CVE JSON 5.1 format and registered as a GNA in the GCVE system

Browse the moksha index

MOGWAI LABS Security Advisories

German offensive security firm founded in 2018, specialising in penetration testing, security assessments, and code reviews. Their "Bug Parade" advisory feed publishes original vulnerability research discovered during engagements and internal research, covering web applications, networks, and cloud environments. Registered as a GNA, publishing advisories in CVE JSON v5 format.

Browse the mogwai-labs index

AHA! — Austin Hackers Anonymous

A collective of independent security researchers and hackers based in Austin, Texas, and one of the first hacker groups to become a CVE Numbering Authority and GCVE Numbering Authority. Founded and led by Tod Beardsley (former CISA Vulnerability Response Section Chief and CVE Board member), AHA! publishes original vulnerability research covering a broad range of software and systems under both CVE and native GCVE identifiers.

Browse the austin-hackers index

Draeger Security Advisories

Draeger Security Advisories are official notifications released by Draeger to address security vulnerabilities and updates in their cloud services and infrastructure. These bulletins provide important information about the vulnerabilities, their potential impact, and recommendations for users to apply necessary patches or configuration changes to ensure the security of their systems.

Browse the draeger index

AWS Relational Database Service Advisories

AWS Relational Database Bulletins are official notifications released by Amazon Web Services to address security vulnerabilities and updates in their cloud services and infrastructure. These bulletins provide important information about the vulnerabilities and version configurations for users to apply necessary patches or configuration changes to ensure the security of their systems.

Browse the aws-rds index

OPC Foundation Security Advisories

Governing body behind OPC UA — the dominant interoperability standard for industrial automation and critical infrastructure. Advisories cover vulnerabilities in OPC UA implementations across 600+ member companies including Siemens, Honeywell, and Rockwell.

Browse the opc-foundation index

Computer Incident Response Center Luxembourg (CIRCL)

The Computer Incident Response Center Luxembourg (CIRCL) is a government-driven initiative designed to gather, review, report and respond to computer security threats and incidents.

Browse the circl index

Vulncheck IOC Threat Actors

The VulnCheck IOC Threat Actors index contains curated indicators of compromise associated with known advanced persistent threat (APT) groups and known threat actors. Threat actors are individuals or organized groups who deliberately conduct malicious cyber operations — often with geopolitical, financial, or espionage motivations — targeting governments, critical infrastructure, and enterprises.

Browse the ioc-threat-actors index

Vulncheck IOC Ransomware

The VulnCheck IOC Ransomware index contains curated indicators of compromise associated with named ransomware groups and their campaigns. Ransomware is a category of malware used by criminal organizations to encrypt victim data or systems and extort payment in exchange for restoration of access.

Browse the ioc.ransomware index

VulnCheck IOC Botnets

The VulnCheck IOC Botnets index contains curated indicators of compromise associated with known botnet families. A botnet is a network of compromised devices under the control of a threat actor, commonly used to conduct distributed denial-of-service attacks, deliver malware, exfiltrate data, or perform large-scale fraud.

Browse the ioc-botnets index

Anthropic Red CVD

Anthropic Red CVD is a disclosure-ledger feed from Anthropic’s Frontier Red Team. It tracks validated findings using sealed-report hashes, disclosure statuses, commitment dates, and, when revealed, identifiers, projects, and bug classes. The feed helps users monitor which findings are pre-disclosure, disclosed, or fixed over time. It is useful for researchers, analysts, and teams tracking AI safety and vulnerability disclosure signals.

Browse the anthropic-cvd index