重要提示:本仓库现在与 CVEProject/cvelist 项目部分冗余,该项目允许使用 git 探索 CVE®/NVD 修改历史,并通过 GitHub pull requests 提交新漏洞。但本仓库仍与字典同步,以便以 JSON 格式获取每个漏洞。
本仓库包含描述来自 NVD 和 CVE® 字典的漏洞的 JSON 文件。
它有两个主要目标:
本仓库中的 JSON 文件是通过 NVD 的 JSON feeds 和 Travis CI 每日生成并更新的。
数据访问:JSON 文件也可通过 https://olbat.github.io/nvdcve/CVE-YYYY-NNNN.json 获取。
CVE® 由 Mitre 公司维护。
本资源(以及本仓库中的 JSON 文件)的使用受 Mitre CVE® 的 使用条款 限制和说明:
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive,
no-charge, royalty-free, irrevocable copyright license to reproduce, prepare
derivative works of, publicly display, publicly perform, sublicense, and
distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for
such purposes is authorized provided that you reproduce MITRE's copyright
designation and this license in any such copy.
国家漏洞数据库 是美国政府基于标准的管理漏洞数据的存储库,使用安全内容自动化协议(SCAP)表示。
它是 CVE® 字典的超集,增加了额外分析、数据库和细粒度搜索引擎。
本资源的使用限制在 NVD 的 FAQ 中有描述:
All NVD data is freely available from our XML Data Feeds. There are no fees,
licensing restrictions, or even a requirement to register. All NIST
publications are available in the public domain according to Title 17 of the
United States Code. Acknowledgment of the NVD when using our information is
appreciated. In addition, please email [email protected] to let us know how the
information is being used.