Using the public Advisory Database
What the public database at /threat-radar/database/ contains, where its data comes from and how it relates to your protected services.
You can find an advisory, read its evidence and check whether it is relevant to your inventory.
What it contains
Over 16,000 advisories normalized from CISA KEV, NVD, GitHub Advisory Database, OSV and ENISA EUVD, scored with EPSS where available. Known-exploited entries are labeled explicitly. The published set grows automatically every day.
What a public entry is not
A public advisory page summarizes third-party data. It says nothing about your systems: relevance requires matching the advisory against the exact packages and versions in your signed inventory - that is what the Coverage Ledger in your dashboard does.
Attribution and licensing
Entries carry per-source attribution: NVD data is public domain, GitHub Advisory content is CC-BY 4.0, CVE content follows the MITRE terms of use, EPSS scores come from FIRST.org.
Verification
- You can open an advisory page and identify its sources
- You know the difference between a public entry and your coverage state