About CoreCVE

A unified view of public vulnerability intelligence. Search, browse, and track CVEs from official sources.

What this is

CoreCVE ingests, normalizes, and stores vulnerability data from official feeds. The public site lets you search and filter CVEs, inspect enriched detail pages (CVSS, KEV, CISA SSVC, EPSS, affected products, CWEs, references), and browse by vendor.

Data is refreshed automatically by background workers. Staging and development instances may use smaller sync windows or sample limits than a full production deployment.

Data sources

CISA KEV

Sync: Daily

Known Exploited Vulnerabilities catalog (actively exploited in the wild).

Official source
NVD

Sync: Every 2 hours (delta)

CVSS, CWE, references, and CPE configurations from NIST.

Official source
MITRE CVE v5

Sync: Every 2 hours (delta)

Authoritative CNA records, often fresher than NVD. Also carries CISA Vulnrichment ADP containers (CVSS, CWE, SSVC) from the same cvelistV5 bundles.

Official source
CISA Vulnrichment

Sync: Daily (full catalog)

Walks cisagov/vulnrichment and applies CISA ADP (CVSS, SSVC, CWE, refs, CPE). MITRE delta also picks up ADP when present in cvelistV5. Does not overwrite NVD/MITRE descriptions.

Official source
OSV

Sync: Daily per ecosystem

Open-source package advisories (Go, npm, Debian, Ubuntu).

Official source
GitHub Security Advisories

Sync: Daily

GHSA↔CVE aliases, GitHub CVSS, CWEs, and advisory references (CVE-linked only).

Official source
FIRST EPSS

Sync: Daily

Exploit Prediction Scoring System probability and percentile.

Official source
API & syndication

The REST API is available at /v1/ on the backend service. OpenAPI description: /v1/openapi.yaml

View live statistics
Known limitations
  • Text search uses substring matching on SQLite and PostgreSQL full-text search (tsvector) when the API runs on Postgres.
  • List severity filters match any current CVSS row. The displayed score is the highest current row.
  • CWE and reference rows are insert-only. Rare NVD removals are not pruned.
  • EPSS and KEV coverage depend on upstream feeds and sync health.