vulnerability-db
Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.
File Explorer
Download Latest Version (.zip)- pythonapp.yml
- pythonpublish.yml
- report_vdb_metadata.py
- sanity_check_vdb.py
- seed_cli_fixture_db.py
- FUNDING.yml
- .gitignore
- index.js
- package.json
- pnpm-lock.yaml
- pnpm-workspace.yaml
- README.md
- deno.json
- deno.lock
- main.ts
- README.md
- bench.md
- bench.py
- bench_baseline.json
- bench_search.py
- cpe_research.py
- match_set.md
- match_set.py
- Picture1.png
- Picture2.png
- Picture3.png
- Picture4.png
- Picture5.png
- Picture6.png
- pin_exposure.py
- reachability_audit.py
- reporting.md
- shard_split.md
- shard_store.md
- vdb_size_report.py
- vers_diff_harness.py
- cvss-v2.0.json
- cvss-v3.0.json
- cvss-v3.1.json
- cvss-v4.0.json
- README.md
- adp-tags.json
- cna-tags.json
- reference-tags.json
- CVE_Record_Format.json
- README.md
- BENCHMARKS.md
- claude-context.png
- claude-permissions.png
- latest-malware.png
- vdb-mcp-inspector.png
- vuln-description.png
- __init__.py
- display.py
- server.py
- conftest.py
- test_db_refresh.py
- test_health_and_shards.py
- test_helpers.py
- test_mcp_sdk_compat.py
- test_server.py
- test_version_sync.py
- .dockerignore
- .gitignore
- Dockerfile
- pyproject.toml
- README.md
- uv.lock
- fast.json
- fast_db_identity.json
- 01_crapi_container_polyglot.json
- 02_docker_rpm_maven.json
- 03_ubuntu_container_deb.json
- 04_k8s_manifest_deb_maven.json
- 05_docker_deb_small.json
- 06_js_npm_nuget.json
- 07_goof_npm.json
- 08_docker_npm.json
- 09_universal_npm_deb.json
- 10_jinja_maven.json
- 11_maven_bom.json
- 12_java_maven.json
- 13_java_vex_maven.json
- 14_evinse_java_maven.json
- 15_cbom_pypi.json
- 17_cargo_smoke.json
- 18_composer_smoke.json
- 19_go_smoke.json
- 20_dotnet_eshop_nuget.json
- 21_dotnet_assets_nuget.json
- 22_poetry_pypi.json
- 23_container_rootfs.json
- 24_wordpress_container_deb.json
- 25_obom_ubuntu2404_deb.json
- 26_obom_ubuntu2204_deb.json
- 27_postgen_maven.json
- 28_jt_maven.json
- 29_ddc_maven.json
- 30_deps_maven.json
- 31_postgen_npm.json
- 32_vuln_spring_maven.json
- 33_crapi_polyglot_monorepo.json
- 34_crapi_polyglot_vex.json
- 35_obom_windows.json
- 36_obom_macos.json
- 37_sles_bci_container_rpm.json
- 38_opensuse_leap_container_rpm.json
- 39_opensuse_tumbleweed_container_rpm.json
- 40_azurelinux_container_rpm.json
- 41_cbl_mariner_container_rpm.json
- 42_azurelinux_container_rpm.json
- 43_cbl_mariner_container_rpm.json
- 44_rockylinux9_container_rpm.json
- 45_almalinux9_container_rpm.json
- 46_oraclelinux9_container_rpm.json
- 47_alpine322_container_apk.json
- 48_alpine3220_container_apk.json
- 49_alpine_edge_container_apk.json
- 50_python312_alpine322_container_apk.json
- 51_debian11_container_deb.json
- 52_debian_sid_forky_container_deb.json
- 53_ubuntu2204_container_deb.json
- 54_ubuntu2404_container_deb.json
- 55_ubuntu1804_bionic_container_deb.json
- 56_ubi9_container_rpm.json
- 57_ubi8_container_rpm.json
- 58_rockylinux9_container_rpm.json
- 59_almalinux9_container_rpm.json
- 60_amazonlinux2023_container_rpm.json
- 61_alpaquita_stream_container_apk.json
- 62_alpaquita_stream_glibc_container_apk.json
- MANIFEST.json
- composer_gitlab_range_from_native.json
- conan_gitlab_range_from_native.json
- gem_gitlab_range_from_native.json
- golang_gitlab_range_from_native.json
- npm_gitlab_range_from_native.json
- pypi_gitlab_range_from_native.json
- conan_range_from_native.json
- conan_range_from_native_basic.json
- gem_range_from_native.json
- nginx_range_from_native.json
- npm_range_containment.json
- npm_range_from_native.json
- nuget_range_from_native.json
- openssl_range_from_native.json
- pypi_range_containment.json
- pypi_range_from_native.json
- pypi_range_roundtrip.json
- alpine_version_cmp.json
- alpm_version_cmp.json
- conan_version_cmp.json
- deb_version_python_pkg_test.json
- gentoo_version_cmp.json
- maven_version_cmp.json
- nuget_version_cmp.json
- openssl_version_cmp.json
- ALAS2022-2022-207.json
- ALSA-2022-8580.json
- aqua-alpine-edge.json
- aqua-alpine-unfixed.json
- AVG-999.json
- CVE-2015-3192.json
- CVE-2018-9840.json
- CVE-2021-27434.json
- CVE-2021-3618-na.json
- CVE-2021-3618.json
- CVE-2023-52426.json
- CVE-2024-0057.json
- CVE-2024-21312.json
- CVE-2024-23771.json
- CVE-2024-25450.json
- CVE-2024-3801.json
- cve_data.json
- cve_wconfig_data.json
- gha_data.json
- gha_prob.json
- GHSA-vc2p-r46x-m3vx.json
- GHSA-xrjj-mj9h-534m.json
- GO-2022-0251.json
- GO-2022-0646.json
- MAL-2024-1333.json
- MAL-2024-1396.json
- MAL-2025-6022.json
- npm_adv_data.json
- npm_data.json
- nvd-CVE-2026-59890.json
- openSUSE-SU-2022-2801-1.json
- os_scan_purls.json
- osv-almalinux-channels.json
- osv-alpine-324-only.json
- osv-alpine-fix.json
- osv-azurelinux-fix-al2.json
- osv-azurelinux-fix.json
- osv-azurelinux-last-affected.json
- osv-bellsoft-alpaquita.json
- osv-bellsoft-hardened.json
- osv-cve-2026-59890.json
- osv-cve-test-npm-org.json
- osv-debian-curl-trixie.json
- osv-debian-dsa.json
- osv-debian-fixed.json
- osv-debian-nopkg.json
- osv-debian-patch-trixie.json
- osv-debian-unfixed.json
- osv-debian-withdrawn.json
- osv-ghsa-cvss4-mistyped-v3.json
- osv-ghsa-cvss4-trailing-slash.json
- osv-git.json
- osv-mageia-single.json
- osv-maven-cvss4.json
- osv-maven-single.json
- osv-npm-star-bug.json
- osv-opensuse-single.json
- osv-opensuse-su-2024-12257-1.json
- osv-opensuse-tumbleweed-bash.json
- osv-opensuse-withdrawn.json
- osv-pypi-django.json
- osv-pypi-ujson-bug.json
- osv-pypi.json
- osv-pypi2.json
- osv-pypi4.json
- osv-redhat-channels.json
- osv-redhat-module.json
- osv-redhat-multi.json
- osv-redhat-nonrhel.json
- osv-redhat-rhba.json
- osv-redhat-single.json
- osv-redhat-withdrawn.json
- osv-rocky-single.json
- osv-suse-bcl.json
- osv-suse-livepatch.json
- osv-suse-multi.json
- osv-suse-nocve.json
- osv-suse-overlap.json
- osv-suse-single.json
- osv-suse-umbrella.json
- osv-ubuntu-cve-2025-46336.json
- osv-ubuntu-fixed.json
- osv-ubuntu-lsn.json
- osv-ubuntu-unfixed.json
- osv-ubuntu-usn.json
- osv-ubuntu-withdrawn.json
- osv_mixed_data.json
- osv_multi_events.json
- osv_mvn_data.json
- osv_rust_data.json
- osv_swift_data.json
- osv_swift_data2.json
- protobuf-c-unfixed.json
- protobuf-c.json
- redis.json
- RLSA-2022-7730.json
- RUSTSEC-2024-0343.json
- SUSE-SU-2015-0439-1.json
- SUSE-SU-2022-4192-1.json
- __init__.py
- deterministic_hash_probe.py
- QUERIES.md
- test_aqua.py
- test_aqua_cache.py
- test_blob_merge.py
- test_cli.py
- test_cpe.py
- test_custom_source.py
- test_db.py
- test_db_cmd.py
- test_db_size.py
- test_deterministic_hashes.py
- test_match_set.py
- test_npm.py
- test_osv.py
- test_osv_bellsoft.py
- test_pin_exposure.py
- test_reachability.py
- test_search_advanced.py
- test_search_bulk.py
- test_shard.py
- test_shard_store.py
- test_source.py
- test_utils.py
- test_vers.py
- __init__.py
- tagger.py
- __init__.py
- comparators.py
- range.py
- __init__.py
- aqua.py
- cna.py
- config.py
- cpe.py
- custom.py
- cve.py
- db.py
- db_cmd.py
- display.py
- gha.py
- npm.py
- nvd.py
- orasclient.py
- osv.py
- search.py
- search_index.py
- shard_split.py
- shard_store.py
- utils.py
- __init__.py
- cli.py
- .dockerignore
- .flake8
- .gitignore
- AGENTS.md
- conftest.py
- INTEGRATION.md
- LICENSE
- MIGRATING_TO_V7.md
- pyproject.toml
- README.md
- SECURITY.md
- SKILL.md
- THREAT_MODEL.md
- uv.lock
// repository documentation
Was this content helpful?
(0 ratings)
