About this project
Built and maintained by William Chen,
a product manager working on security and platform software. This started as a question worth
answering rather than a product with a plan: vulnerability data is published for people who already
understand it, and everyone else is locked out of the one question they actually have.
It is free, open source, and has nothing to sell you.
How this stays current
Rebuilt automatically every day at 06:17 UTC, straight from the source data.
New entries are added to the catalog three or four days a week, around 25 a month,
so most days nothing changes — which is the point. Only vulnerabilities confirmed
to be under active attack appear here at all.
Built on the CISA Known Exploited Vulnerabilities catalog
and the CVE Program record repository.
Nobody updates this by hand.
This explains public vulnerability data in ordinary language. It does not scan your
devices, does not know what you own, and is not a substitute for advice about your
specific setup.
Source on GitHub