Data sources and licences
The tools and threat pages on this site are built on public data. This page lists which datasets we use, on which pages, and under what terms. Notices that a provider asks us to show are quoted word for word.
Updated 2026-10-10
Key points
- We only use public data whose published terms allow use on a commercial, ad-supported site.
- The notices required by NVD and MITRE (CWE and ATT&CK) are quoted on this page exactly as the providers wrote them.
- Incident records rely first on the affected organisation's own disclosure, and we never name attacker groups.
At a glance
| Dataset | Where we use it | Licence / terms |
|---|---|---|
| CISA KEV (Known Exploited Vulnerabilities) | Threat feed, live threat picture, CVE / KEV Lookup | CC0 1.0 |
| NVD (National Vulnerability Database) | Threat feed, CVE / KEV Lookup | NVD terms of use |
| FIRST EPSS (Exploit Prediction Scoring System) | Threat feed, live threat picture, CVE / KEV Lookup | Free to use (credit requested) |
| MITRE CWE (Common Weakness Enumeration) | CVE / KEV Lookup, Glossary | CWE terms of use (commercial use allowed, copyright notice required) |
| MITRE ATT&CK | Glossary | ATT&CK terms of use (commercial use allowed, copyright notice required) |
| OSV.dev / GitHub Advisory Database | Dependency Vulnerability Scanner | Varies by source (GitHub Advisory: CC BY 4.0) |
| Cloudflare Radar | Live threat picture | Embeds: CC BY 4.0 |
| Have I Been Pwned (breach data) | Live threat picture | CC BY 4.0 |
| Pwned Passwords | Password Strength, Leak Check & Generator | No attribution requirement (we credit it anyway) |
CISA KEV (Known Exploited Vulnerabilities)
A catalogue of vulnerabilities that are confirmed to be exploited in the wild, published by the US Cybersecurity and Infrastructure Security Agency (CISA). Official page
- What we use it for
- We use it to tell whether a vulnerability is actually being exploited. It drives the priority in the threat feed, the “KEV additions in the last 7 days” on the live threat picture, and the “actively exploited” flag in the CVE / KEV Lookup.
- Licence / terms
- CC0 1.0 (public domain dedication). No notice is required, but we credit the source anyway.
NVD (National Vulnerability Database)
Run by the US National Institute of Standards and Technology (NIST). Official site
- What we use it for
- We fetch each CVE's severity (CVSS), affected products, weakness type (CWE) and reference links. These appear in the threat feed and the CVE / KEV Lookup. The lookup calls the NVD API only for CVEs that are not already in this site's database.
- Licence / terms
- The NVD terms of use allow commercial use. They require the notice below, which we show word for word on this page and on the CVE / KEV Lookup.
- Required notice (verbatim)
This product uses the NVD API but is not endorsed or certified by the NVD.
FIRST EPSS (Exploit Prediction Scoring System)
A daily estimate of how likely each CVE is to be exploited in the next 30 days, published by FIRST, the global forum of incident response teams. Official page
- What we use it for
- We show each CVE's exploit probability and percentile as a guide to what to patch first, in the threat feed, the live threat picture and the CVE / KEV Lookup.
- Licence / terms
- The EPSS usage terms make it free to use and ask users to credit it with the line below.
- Required notice (verbatim)
See EPSS at https://www.first.org/epss
MITRE CWE (Common Weakness Enumeration)
A list of software weakness types, maintained by the US non-profit MITRE. Official site
- What we use it for
- The CVE / KEV Lookup shows which kind of weakness a CVE is (its CWE ID). Some glossary entries also list related CWE IDs. We only use the IDs and names; we do not copy CWE's descriptions.
- Licence / terms
- The CWE terms of use allow research, development and commercial use, on the condition that MITRE's copyright designation and the licence are reproduced. Both are quoted below.
- Required notice (verbatim)
Copyright © 2006–2026, The MITRE Corporation. CWE is a trademark of The MITRE Corporation.
The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. Any copy you make for such purposes is authorized on the condition that you reproduce MITRE’s copyright designation and this license in any such copy.
MITRE ATT&CK
A knowledge base of attacker behaviour organised by tactic and technique, maintained by MITRE. Official site
- What we use it for
- Some glossary entries list related technique IDs (for example T1566) as a pointer for looking up defences. We do not use ATT&CK's information on attacker groups (Groups).
- Licence / terms
- The ATT&CK terms of use allow research, development and commercial use, on the condition that MITRE's copyright designation and the licence are reproduced. Both are quoted below.
- Required notice (verbatim)
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
OSV.dev / GitHub Advisory Database
An open vulnerability database run by Google. Its npm data comes mainly from the GitHub Advisory Database. OSV.dev
- What we use it for
- The Dependency Vulnerability Scanner checks the packages you paste against known vulnerabilities. Queries go straight from your browser to OSV.dev and never pass through this site's server.
- Licence / terms
- OSV.dev data is licensed per source, as listed in the OSV data documentation. The GitHub Advisory Database, the main source for npm, is CC BY 4.0. Each result shows the advisory ID and links to its original page on OSV.dev.
Cloudflare Radar
Cloudflare's public observations of internet traffic and attacks. Official site
- What we use it for
- The live threat picture embeds Radar charts of DDoS attack volume and the top source and target countries. The embedded charts load from Cloudflare's servers, and Cloudflare Web Analytics measures their use. See our privacy policy for details.
- Licence / terms
- Embedded cards and images are offered under CC BY 4.0 (About Radar), and every chart carries a source line. Numbers from the Radar API and CSV downloads are licensed for non-commercial use only (CC BY-NC 4.0), so we do not import them.
Have I Been Pwned (breach data)
A database of publicly reported data breaches, run by a security researcher. Official site
- What we use it for
- The live threat picture shows how many breaches were added recently and which kinds of data they exposed. We show totals only and do not name the organisations, because a listed breach is not always one the organisation itself has disclosed.
- Licence / terms
- The breach API is licensed under CC BY 4.0 (API documentation). We link to Have I Been Pwned as the source and state that the totals are our own count.
Pwned Passwords
A list of password hashes found in past breaches, provided by Have I Been Pwned. Official page
- What we use it for
- The Password Strength, Leak Check & Generator tool checks whether a password appears in past breaches. Your browser hashes the password and sends only the first five characters of the hash (k-anonymity), so the password itself is never sent anywhere.
- Licence / terms
- Have I Been Pwned's CC BY 4.0 licence covers its breach APIs; the Pwned Passwords API carries no attribution requirement. We credit it as the source anyway.
How we handle incident data
- Incident records rely first on the affected organisation's own disclosure, then on regulators' announcements, and only then on press reports. Every entry cites the sources it is based on.
- Only the affected organisation is named. Third parties such as contractors, vendors and investigators are described by their role.
- We do not name attacker groups or use information that comes from criminals' leak sites.
- When follow-up reports change the facts, we correct the record and note what changed and when. The list is in Data breaches and cyberattacks of 2026: a timeline and in Incidents & Vulnerabilities.
How we choose data
- We only use data whose published terms allow use on a commercial, ad-supported site. Anything limited to non-commercial use, or whose terms we cannot confirm, is left out.
- We re-read a provider's terms before starting any new use of its data, because terms change.
- What this site shows is a copy. Check the provider's original for the exact, current values.
- Passwords and dependency lists you enter in our tools never pass through this site's server. Those checks go straight from your browser to the data provider.
If you spot a missing credit or an error, please let us know via the contact page.