{
  "about": "What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.",
  "built_at": 1790705242,
  "built_by": "zetlyn 0.2.0",
  "checked_against": {},
  "declaration": "name: zetlyn/cve\ntitle: CVE\nabout: What each publisher says about a vulnerability, whether working code exists for it, and what is written about it afterwards.\nsources:\n- source: zetlyn/cve-kev\n  priority: primary\n  why: The only source that says a vulnerability is being exploited right now.\n- source: zetlyn/cve-redhat\n  priority: high\n  why: Its own severity, and the packages it tracks a vulnerability in.\n- source: zetlyn/cve-nvd\n  priority: high\n  why: The CVSS baseline, and an anchor for CVEs the other members never reach.\n- source: zetlyn/cve-ghsa\n  priority: high\n  why: The ecosystem packages no distribution ships.\n- source: zetlyn/cve-metasploit\n  why: Whether a module exists for the tool an attacker actually runs.\n- source: zetlyn/cve-exploitdb\n  why: Whether working code exists at all, which is a different question from how severe it is.\n- source: zetlyn/cve-writeups\n  why: The prose that explains a vulnerability after the advisories have stopped.\nidentified_by:\n- cve\n# What a vulnerability is to something else, where a claim states both: NVD names the CPEs of what\n# it affects once it has analysed a CVE. Where it has not, the CNA's own words are offered to a\n# person to confirm, and a match they confirm is theirs, signed, in matches.jsonl.\nrelations:\n- name: affects\n  to: cpe\n  as: product\n  suggest_from: [vendor, product]\n  about: The products it affects, as vendor/product.\n- name: made_by\n  to: cpe\n  as: vendor\n  suggest_from: [vendor]\n  about: The vendors whose products it affects.\nalign:\n  # The same number from every source that scores one: NVD, Red Hat and GitHub all give a CVSS\n  # base score, and a difference between them is a difference of judgement.\n  cvss: {}\n  # Exploited means somebody is using it, and one source says that: CISA, by putting the row in\n  # its catalogue. Metasploit's rank and Exploit-DB's verified flag are about the code, not about\n  # the attack — a module that nobody has fired and an unverified proof of concept are both code\n  # that exists. That question is already answered, by a claim of kind `exploit`, and 23,444\n  # things carry one. Reading the two as one property makes `exploited=yes` useless for triage.\n  exploited:\n    scale:\n    - \"yes\"\n    - \"no\"\n  severity:\n    scale:\n    - critical\n    - high\n    - medium\n    - low\n    - unknown\n    zetlyn/cve-ghsa:\n      critical: critical\n      high: high\n      low: low\n      moderate: medium\n    zetlyn/cve-redhat:\n      critical: critical\n      important: high\n      low: low\n      moderate: medium\nview:\n  columns:\n  - kind\n  - severity\n  - cvss\n  - known\n  facets:\n  - kind\n  - source\n  - severity\n  - exploited\n  sort: known desc\n  named:\n  - name: exploited-and-severe\n    title: Exploited, and severe\n    where: exploited=yes and severity>=high\n  exploit:\n    adopt: zetlyn/cve-exploitdb:verified\npromise:\n  fresh_within: 24h\n  covers: Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE.\n  excludes: Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.\n",
  "identified_by": [
    "cve"
  ],
  "promise": {
    "covers": "Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE.",
    "excludes": "Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.",
    "fresh_within": "24h"
  },
  "signed_by": "ed25519:af9ffd7b7435cdad9724db5feea1a6f55ff38ea13b860ab62260f34f59a131ab",
  "sources": [
    "zetlyn/cve-kev",
    "zetlyn/cve-redhat",
    "zetlyn/cve-nvd",
    "zetlyn/cve-ghsa",
    "zetlyn/cve-metasploit",
    "zetlyn/cve-exploitdb",
    "zetlyn/cve-writeups"
  ],
  "spec_version": "2.1",
  "title": "CVE",
  "tracker": "zetlyn/cve",
  "version": "5bda63e4b97629a5ce406ca4"
}