Documentation/Data sources

Data sources

DevSecure Intelligence fuses public vulnerability, exploitation, advisory, and patch signals into one API.

NVD

CVSS scores, attack vectors, and CWE mappings. Refreshed daily.

EPSS

30-day exploitation probability from FIRST. Refreshed daily.

CISA KEV

Confirmed active exploitation signal from CISA. Refreshed daily.

GHSA

GitHub advisory context. Refreshed hourly.

OSV

Ecosystem-specific vulnerability data. Refreshed daily.

MITRE

Canonical CVE metadata. Refreshed weekly.

ExploitDB and public exploit feeds

Public exploit availability and exploit-context signals. Refreshed daily.

MoreFixes

Verified patch evidence. Refresh posture is product-controlled.

Freshness appears in data_quality.last_source_refresh for enriched CVE responses and in the /api/v1/status endpoint for API-level health.

See API Reference: GET /api/v1/status and API Reference: DataQualityBlock.