Rage about CVE dataset quality(?)

This page summarizes the projects mentioned and recommended in the original post on /r/cybersecurity

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • cvelistV5

    CVE cache of the official CVE List in CVE JSON 5.0 format

  • 118955 entries don't even have an affected vendor/product software field, and neither with a valid version string and/or condition. They only contain plaintext descriptions and no version matching field either. Filed an issue here about it.

  • Loki

    Loki - Simple IOC and YARA Scanner (by Neo23x0)

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • cvelist

    Pilot program for CVE submission through GitHub. CVE Record Submission via Pilot PRs ending 6/30/2023

  • The upcoming v5 format is here: https://github.com/CVEProject/cvelist

  • cve-schema

    This repository is used for the development of the CVE JSON record format. Releases of the CVE JSON record format will also be published here. This repository is managed by the CVE Quality Working Group.

  • I adopted JSON for the CVE data format when I invented it (https://github.com/CVEProject/cve-schema/tree/master/schema ) for two main reasons:

  • gsd-tools

    Global Security Database Tools

  • SQL won't prevent data errors any more than using JSON, you can have schema validation and the exact same data validation tooling, which we'd be more than happy to have, if you want to build this simply submit PR's against the tools repo: https://github.com/cloudsecurityalliance/gsd-tools

  • opencve

    CVE Alerting Platform

  • You might want to check OpenCVE: https://github.com/opencve/opencve

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts