INTELLIGENCE / HISTORICAL RECORDS
CVE & KEV archive_
Sources, coverage and update status
Records are supplied by the CVE Program, including the assigning CNA and additional data providers. Listed products are those mentioned in a record, not a determination that every version is affected. Consult the original affected-version conditions. Rejected records are retained separately and are not active vulnerability claims.
The summary selects CNA CVSS first (4.0, then 3.1, 3.0, 2.0); ADP scores are a fallback. A severity score is not evidence of exploitation. NVD analysis and FIRST EPSS are available through the live per-CVE enrichment view; they are not bulk-mirrored here.
KEV due dates apply to US federal civilian executive branch agencies under the applicable CISA directive—not automatically to your organization. Absence from KEV does not prove a vulnerability is unexploited.