Terms of use

Informational catalogue — not security advice.

What this site is

CoreCVE is a convenience view over public vulnerability feeds. It is provided as-is, without warranty of completeness, accuracy, or fitness for a particular purpose.

Not advice

Nothing on this site is a substitute for vendor advisories, your own risk assessment, or professional security advice. Presence or absence of a CVE, KEV flag, CVSS score, or EPSS value must not be the sole basis for a patching or exposure decision.

Upstream data

Scores, dates, products, and descriptions come from third parties (including CISA, NIST NVD, MITRE/CVE.org, OSV, GitHub, Red Hat, FIRST). They can lag, conflict, or be corrected later. When sources disagree, CoreCVE shows what it ingested; it does not certify a “true” record.

Use of the API

Automated access to the public API is allowed for reasonable personal or research use. Do not overload the service. We may rate-limit or block abusive clients.

Trademarks

CVE® is a registered trademark of The MITRE Corporation. Other product and project names remain the property of their owners. See also the legal notice.