Transparency
Data Sources & Attribution
Every claim published here traces to one of the feeds below. This page lists each one with its provider, licence and the attribution its terms require.
Ingested sources
-
CISA Known Exploited Vulnerabilities Catalog
Cybersecurity and Infrastructure Security Agency
Source: CISA Known Exploited Vulnerabilities Catalog
Licence: U.S. Government work (public domain) · terms last reviewed 2026-09-13
-
CISA Vulnrichment (CVE record ADP container)
Cybersecurity and Infrastructure Security Agency (CISA)
Source: CISA Vulnrichment (CC0 1.0), via the CVE List
Licence: CC0-1.0 · terms last reviewed 2026-09-24
-
CVE Program (CVE List v5)
MITRE / CVE Program
CVE and the CVE logo are trademarks of The MITRE Corporation; CVE record data used under CVE Program terms.
Licence: CVE Program Terms of Use · terms last reviewed 2026-09-13
-
FIRST Exploit Prediction Scoring System (EPSS)
FIRST.org
EPSS score provided by FIRST.org (first.org/epss)
Licence: FIRST EPSS data use policy · terms last reviewed 2026-09-13
-
GitHub Advisory Database
GitHub
Source: GitHub Advisory Database (CC-BY-4.0)
Licence: CC-BY-4.0 · terms last reviewed 2026-09-14
-
Microsoft Security Response Center (Security Update Guide)
Microsoft
Source: Microsoft Security Response Center
Licence: Microsoft API Terms of Use · terms last reviewed 2026-09-13
-
MITRE ATT&CK
MITRE
MITRE ATT&CK® — https://attack.mitre.org
Licence: MITRE ATT&CK Terms of Use · terms last reviewed 2026-09-13
-
National Vulnerability Database
NIST
This product uses the NVD API but is not endorsed or certified by the NVD.
Licence: NVD terms of use · terms last reviewed 2026-09-14
-
Red Hat Security Data API (CVE list)
Red Hat
Source: Red Hat Product Security, Security Data (https://access.redhat.com/security/data), licensed under CC BY 4.0. Analysis and derived statistics are Quietlytic’s own.
Licence: CC-BY-4.0 · terms last reviewed 2026-09-24
-
VulnCheck Known Exploited Vulnerabilities (Community)
VulnCheck
VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV)
Licence: VulnCheck KEV Community terms · terms last reviewed 2026-09-14
Source data is synthesised into original analysis; vendor advisory and third-party report text is never reproduced verbatim. Where a source and our assessment disagree, both are stated rather than reconciled silently. Corrections: see our editorial & corrections policy.