Skip to content
>_ITDITDWeb Security Platform
Sources

Data sources and licences

The tools and threat pages on this site are built on public data. This page lists which datasets we use, on which pages, and under what terms. Notices that a provider asks us to show are quoted word for word.

Updated 2026-10-10

Key points

  • We only use public data whose published terms allow use on a commercial, ad-supported site.
  • The notices required by NVD and MITRE (CWE and ATT&CK) are quoted on this page exactly as the providers wrote them.
  • Incident records rely first on the affected organisation's own disclosure, and we never name attacker groups.

At a glance

DatasetWhere we use itLicence / terms
CISA KEV (Known Exploited Vulnerabilities)Threat feed, live threat picture, CVE / KEV LookupCC0 1.0
NVD (National Vulnerability Database)Threat feed, CVE / KEV LookupNVD terms of use
FIRST EPSS (Exploit Prediction Scoring System)Threat feed, live threat picture, CVE / KEV LookupFree to use (credit requested)
MITRE CWE (Common Weakness Enumeration)CVE / KEV Lookup, GlossaryCWE terms of use (commercial use allowed, copyright notice required)
MITRE ATT&CKGlossaryATT&CK terms of use (commercial use allowed, copyright notice required)
OSV.dev / GitHub Advisory DatabaseDependency Vulnerability ScannerVaries by source (GitHub Advisory: CC BY 4.0)
Cloudflare RadarLive threat pictureEmbeds: CC BY 4.0
Have I Been Pwned (breach data)Live threat pictureCC BY 4.0
Pwned PasswordsPassword Strength, Leak Check & GeneratorNo attribution requirement (we credit it anyway)

CISA KEV (Known Exploited Vulnerabilities)

A catalogue of vulnerabilities that are confirmed to be exploited in the wild, published by the US Cybersecurity and Infrastructure Security Agency (CISA). Official page

What we use it for
We use it to tell whether a vulnerability is actually being exploited. It drives the priority in the threat feed, the “KEV additions in the last 7 days” on the live threat picture, and the “actively exploited” flag in the CVE / KEV Lookup.
Licence / terms
CC0 1.0 (public domain dedication). No notice is required, but we credit the source anyway.

NVD (National Vulnerability Database)

Run by the US National Institute of Standards and Technology (NIST). Official site

What we use it for
We fetch each CVE's severity (CVSS), affected products, weakness type (CWE) and reference links. These appear in the threat feed and the CVE / KEV Lookup. The lookup calls the NVD API only for CVEs that are not already in this site's database.
Licence / terms
The NVD terms of use allow commercial use. They require the notice below, which we show word for word on this page and on the CVE / KEV Lookup.
Required notice (verbatim)

This product uses the NVD API but is not endorsed or certified by the NVD.

FIRST EPSS (Exploit Prediction Scoring System)

A daily estimate of how likely each CVE is to be exploited in the next 30 days, published by FIRST, the global forum of incident response teams. Official page

What we use it for
We show each CVE's exploit probability and percentile as a guide to what to patch first, in the threat feed, the live threat picture and the CVE / KEV Lookup.
Licence / terms
The EPSS usage terms make it free to use and ask users to credit it with the line below.
Required notice (verbatim)

See EPSS at https://www.first.org/epss

MITRE CWE (Common Weakness Enumeration)

A list of software weakness types, maintained by the US non-profit MITRE. Official site

What we use it for
The CVE / KEV Lookup shows which kind of weakness a CVE is (its CWE ID). Some glossary entries also list related CWE IDs. We only use the IDs and names; we do not copy CWE's descriptions.
Licence / terms
The CWE terms of use allow research, development and commercial use, on the condition that MITRE's copyright designation and the licence are reproduced. Both are quoted below.
Required notice (verbatim)

Copyright © 2006–2026, The MITRE Corporation. CWE is a trademark of The MITRE Corporation.

The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. Any copy you make for such purposes is authorized on the condition that you reproduce MITRE’s copyright designation and this license in any such copy.

MITRE ATT&CK

A knowledge base of attacker behaviour organised by tactic and technique, maintained by MITRE. Official site

What we use it for
Some glossary entries list related technique IDs (for example T1566) as a pointer for looking up defences. We do not use ATT&CK's information on attacker groups (Groups).
Licence / terms
The ATT&CK terms of use allow research, development and commercial use, on the condition that MITRE's copyright designation and the licence are reproduced. Both are quoted below.
Required notice (verbatim)

© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

OSV.dev / GitHub Advisory Database

An open vulnerability database run by Google. Its npm data comes mainly from the GitHub Advisory Database. OSV.dev

What we use it for
The Dependency Vulnerability Scanner checks the packages you paste against known vulnerabilities. Queries go straight from your browser to OSV.dev and never pass through this site's server.
Licence / terms
OSV.dev data is licensed per source, as listed in the OSV data documentation. The GitHub Advisory Database, the main source for npm, is CC BY 4.0. Each result shows the advisory ID and links to its original page on OSV.dev.

Cloudflare Radar

Cloudflare's public observations of internet traffic and attacks. Official site

What we use it for
The live threat picture embeds Radar charts of DDoS attack volume and the top source and target countries. The embedded charts load from Cloudflare's servers, and Cloudflare Web Analytics measures their use. See our privacy policy for details.
Licence / terms
Embedded cards and images are offered under CC BY 4.0 (About Radar), and every chart carries a source line. Numbers from the Radar API and CSV downloads are licensed for non-commercial use only (CC BY-NC 4.0), so we do not import them.

Have I Been Pwned (breach data)

A database of publicly reported data breaches, run by a security researcher. Official site

What we use it for
The live threat picture shows how many breaches were added recently and which kinds of data they exposed. We show totals only and do not name the organisations, because a listed breach is not always one the organisation itself has disclosed.
Licence / terms
The breach API is licensed under CC BY 4.0 (API documentation). We link to Have I Been Pwned as the source and state that the totals are our own count.

Pwned Passwords

A list of password hashes found in past breaches, provided by Have I Been Pwned. Official page

What we use it for
The Password Strength, Leak Check & Generator tool checks whether a password appears in past breaches. Your browser hashes the password and sends only the first five characters of the hash (k-anonymity), so the password itself is never sent anywhere.
Licence / terms
Have I Been Pwned's CC BY 4.0 licence covers its breach APIs; the Pwned Passwords API carries no attribution requirement. We credit it as the source anyway.

How we handle incident data

  • Incident records rely first on the affected organisation's own disclosure, then on regulators' announcements, and only then on press reports. Every entry cites the sources it is based on.
  • Only the affected organisation is named. Third parties such as contractors, vendors and investigators are described by their role.
  • We do not name attacker groups or use information that comes from criminals' leak sites.
  • When follow-up reports change the facts, we correct the record and note what changed and when. The list is in Data breaches and cyberattacks of 2026: a timeline and in Incidents & Vulnerabilities.

How we choose data

  • We only use data whose published terms allow use on a commercial, ad-supported site. Anything limited to non-commercial use, or whose terms we cannot confirm, is left out.
  • We re-read a provider's terms before starting any new use of its data, because terms change.
  • What this site shows is a copy. Check the provider's original for the exact, current values.
  • Passwords and dependency lists you enter in our tools never pass through this site's server. Those checks go straight from your browser to the data provider.

If you spot a missing credit or an error, please let us know via the contact page.