
매일 업데이트되는 NVD/CVE 취약점 데이터의 JSON 저장소로, 보안 연구 및 취약점 관리를 위한 CVE 수정 내역의 손쉬운 검색 및 git 기반 탐색을 가능하게 합니다.
중요: 이 저장소는 현재 CVEProject/cvelist 프로젝트와 부분적으로 중복됩니다. 해당 프로젝트는 git을 사용하여 CVE®/NVD 수정 기록을 탐색하고 GitHub 풀 리퀘스트를 통해 새로운 취약점을 제출할 수 있게 해줍니다. 하지만 이 저장소는 여전히 사전과 동기화되어 각 취약점을 JSON 형식으로 가져올 수 있도록 합니다.
이 저장소에는 NVD 및 CVE® 사전의 취약점을 설명하는 JSON 파일이 포함되어 있습니다.
두 가지 주요 목표가 있습니다:
이 저장소의 JSON 파일은 NVD의 JSON 피드와 Travis CI를 사용하여 매일 생성 및 업데이트됩니다.
데이터 접근: JSON 파일은 https://olbat.github.io/nvdcve/CVE-YYYY-NNNN.json에서도 가져올 수 있습니다.
CVE®는 Mitre Corporation에서 유지 관리합니다.
이 리소스와 이 저장소의 JSON 파일의 사용은 Mitre CVE®의 이용 약관에 따라 제한되며 설명되어 있습니다:
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive,
no-charge, royalty-free, irrevocable copyright license to reproduce, prepare
derivative works of, publicly display, publicly perform, sublicense, and
distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for
such purposes is authorized provided that you reproduce MITRE's copyright
designation and this license in any such copy.
National Vulnerability Database는 보안 콘텐츠 자동화 프로토콜(SCAP)을 사용하여 표현된 표준 기반 취약점 관리 데이터의 미국 정부 저장소입니다.
이는 추가 분석, 데이터베이스 및 세분화된 검색 엔진으로 보강된 CVE® 사전의 상위 집합입니다.
이 리소스의 사용 제한 사항은 NVD의 FAQ에 설명되어 있습니다:
All NVD data is freely available from our XML Data Feeds. There are no fees,
licensing restrictions, or even a requirement to register. All NIST
publications are available in the public domain according to Title 17 of the
United States Code. Acknowledgment of the NVD when using our information is
appreciated. In addition, please email [email protected] to let us know how the
information is being used.