Legal
Data Sources and Licences
Last updated: 5 October 2026
DevSecure Intelligence combines public vulnerability data with our own scoring (the Risk Priority Score) and enrichment. This page lists every third-party source we use, the licence it is published under, and the credit or notice that licence asks for. Where a source requires attribution, the same attribution applies to anyone who receives that data from us.
NATIONAL VULNERABILITY DATABASE (NVD)
CVE records, CVSS scores and CPE data from the U.S. National Institute of Standards and Technology. This product uses data from the NVD API but is not endorsed or certified by the NVD. Source: nvd.nist.gov.
CVE PROGRAM
CVE identifiers and descriptions from the CVE Program. Copyright © 1999–2026, The MITRE Corporation. CVE and the CVE logo are registered trademarks of The MITRE Corporation. CVE content is reproduced and distributed under the CVE Program's terms of use, which grant a perpetual, worldwide, non-exclusive, royalty-free licence to reproduce, prepare derivative works of, and distribute CVE content, provided this copyright designation and licence are reproduced. Terms: cve.org/Legal/TermsOfUse.
EXPLOIT PREDICTION SCORING SYSTEM (EPSS)
EPSS scores and percentiles by FIRST.org. EPSS is free to use. Source: first.org/epss.
CISA KNOWN EXPLOITED VULNERABILITIES (KEV)
The Known Exploited Vulnerabilities Catalog from the U.S. Cybersecurity and Infrastructure Security Agency, published under CC0 1.0. Its use here does not imply endorsement by CISA. Source: cisa.gov/known-exploited-vulnerabilities-catalog.
GITHUB ADVISORY DATABASE (GHSA)
Security advisories from the GitHub Advisory Database, © GitHub, Inc., licensed under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). We normalise advisory fields and join them to CVE records. Source: github.com/github/advisory-database.
OPEN SOURCE VULNERABILITIES (OSV)
Vulnerability data aggregated by OSV.dev. The OSV data is made available under CC BY 4.0; each upstream source in OSV keeps its own licence (most are CC BY 4.0, some CC0 1.0 or Apache 2.0), and those licences apply to the records we use. We use affected-package and ecosystem fields. Source and per-source licences: google.github.io/osv.dev/data.
MOREFIXES
Historical vulnerability-fixing commits from the MoreFixes dataset (Akhoundali et al.), licensed under CC BY 4.0. The repositories the commits come from keep their own licences. Source: github.com/JafarAkhondali/morefixes.
EXPLOIT DATABASE
Exploit metadata (exploit identifiers, the CVEs an exploit references, publication dates) from the Exploit Database by OffSec. We use metadata to indicate that a public exploit exists; we do not redistribute exploit code. The Exploit Database repository is published under the GNU General Public License v2.0 or later. Source: exploit-db.com.
MITRE CWE AND ATT&CK
Weakness classifications (CWE) and adversary technique mappings (ATT&CK) from The MITRE Corporation, used under MITRE's terms of use for CWE and ATT&CK. CWE and ATT&CK are trademarks of The MITRE Corporation. Sources: cwe.mitre.org, attack.mitre.org.
FIX COMMITS FROM PUBLIC REPOSITORIES
Our patch intelligence links CVEs to fixing commits in public source repositories. Code in those repositories remains under each repository's own licence. Where we show code from a fix, that licence applies to it.
OUR OWN DATA
The Risk Priority Score (RPS), its methodology, rankings, explanations and our enrichment are © DevSecure Limited. Use of API responses is governed by our Terms and Acceptable Use Policy. Redistribution of DevSecure data (including any third-party data above) requires a written agreement, which passes through the third-party licence obligations listed on this page.
QUESTIONS OR CORRECTIONS
If you believe a credit here is missing or incorrect, email help@devsecure.io and we'll correct it.