> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-g/20-20-final-structure-for-all-vulnerability-management-sources-and-exposure-listing.md).

# 20. Final structure for all vulnerability management sources & exposure listings

<table><thead><tr><th width="90.91796875" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>Canonical vulnerability records</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/CVEProject/cvelistV5">github.com/CVEProject/cvelistV5</a>, <a href="https://github.com/cisagov/vulnrichment">github.com/cisagov/vulnrichment</a>, <a href="https://nvd.nist.gov/">nvd.nist.gov</a>, <a href="https://www.cve.org/">www.cve.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open-source; NVD optional API key</td><td><strong><code>Relevance</code>:</strong> CVE, NVD, CVE schema, &#x26; CISA Vulnrichment provide base vulnerability identity &#x26; enrichment.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use as foundational sources but enrich with vendor/package-specific affectedness.</td></tr><tr><td align="right">2</td><td><strong>Package &#x26; ecosystem advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/advisories">github.com/advisories</a>, <a href="https://github.com/github/advisory-database">github.com/github/advisory-database</a>, <a href="https://osv.dev/">osv.dev</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open-source</td><td><strong><code>Relevance</code>:</strong> OSV, GHSA, &#x26; language advisory DBs provide package-level affected version data.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Prefer PURL/package semantics over CPE for OSS dependencies.</td></tr><tr><td align="right">3</td><td><strong>Vendor &#x26; distro affectedness</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://access.redhat.com/security/data">access.redhat.com/security/data</a>, <a href="https://secdb.alpinelinux.org/">secdb.alpinelinux.org</a>, <a href="https://security-tracker.debian.org/">security-tracker.debian.org</a>, <a href="https://ubuntu.com/security/oval">ubuntu.com/security/oval</a>, <a href="https://www.suse.com/support/security/csaf/">www.suse.com/support/security/csaf</a><br><br><strong><code>Access / Cost</code>:</strong> Mostly free public; some vendor support entitlements may apply</td><td><strong><code>Relevance</code>:</strong> CSAF, VEX, OVAL, secdb, OSV, &#x26; vendor advisories identify whether a specific product/package is affected.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Essential for reducing false positives &#x26; handling backports.</td></tr><tr><td align="right">4</td><td><strong>Exploitability &#x26; prioritization</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/rapid7/metasploit-framework">github.com/rapid7/metasploit-framework</a>, <a href="https://viz.greynoise.io/">viz.greynoise.io</a>, <a href="https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json">www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json</a>, <a href="https://www.exploit-db.com/">www.exploit-db.com</a>, <a href="https://www.first.org/epss/">www.first.org/epss</a><br><br><strong><code>Access / Cost</code>:</strong> Mixed: free public, open-source, free tiers / paid plans</td><td><strong><code>Relevance</code>:</strong> KEV, EPSS, SSVC, CVSS, Exploit-DB, Metasploit, &#x26; GreyNoise inform urgency.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Do not conflate severity with exploitability.</td></tr><tr><td align="right">5</td><td><strong>Weakness &#x26; adversary mapping</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://attack.mitre.org/matrices/enterprise/">attack.mitre.org/matrices/enterprise</a>, <a href="https://atlas.mitre.org/">atlas.mitre.org</a>, <a href="https://capec.mitre.org/">capec.mitre.org</a>, <a href="https://cwe.mitre.org/">cwe.mitre.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> CWE, CAPEC, ATT&#x26;CK, &#x26; ATLAS map vulnerabilities to weaknesses &#x26; adversary behavior.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for detection engineering &#x26; root-cause analysis.</td></tr><tr><td align="right">6</td><td><strong>AI-specific vulnerability context</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://atlas.mitre.org/">atlas.mitre.org</a>, <a href="https://owasp.org/www-project-machine-learning-security-top-10/">owasp.org/www-project- machine-learning-security-top-10</a>, <a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/">owasp.org/www-project-top-10-for-large-language-model-applications</a>, <a href="https://www.nist.gov/itl/ai-risk-management-framework">www.nist.gov/itl/ai-risk-management-framework</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open community</td><td><strong><code>Relevance</code>:</strong> ATLAS, OWASP LLM Top 10, OWASP ML Top 10, &#x26; NIST AI RMF frame AI/ML risk.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> AI vulnerabilities often lack CVEs; include threat-model &#x26; control frameworks.</td></tr><tr><td align="right">7</td><td><strong>SBOM &#x26; identity</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cyclonedx.org/specification/overview/">cyclonedx.org/specification/overview</a>, <a href="https://github.com/package-url/purl-spec">github.com/package-url/purl-spec</a>, <a href="https://nvd.nist.gov/products/cpe">nvd.nist.gov/products/cpe</a>, <a href="https://spdx.dev/specifications/">spdx.dev/specifications</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open standards</td><td><strong><code>Relevance</code>:</strong> CycloneDX, SPDX, PURL, CPE, &#x26; SWID identify components for matching.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Accurate inventory is prerequisite to vulnerability assessment.</td></tr><tr><td align="right">8</td><td><strong>Exposure telemetry</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://leakix.net/">leakix.net</a>, <a href="https://search.censys.io/">search.censys.io</a>, <a href="https://viz.greynoise.io/">viz.greynoise.io</a>, <a href="https://www.shadowserver.org/">www.shadowserver.org</a>, <a href="https://www.shodan.io/">www.shodan.io</a><br><br><strong><code>Access / Cost</code>:</strong> Mixed: free public, free tiers, paid plans, registration-based access</td><td><strong><code>Relevance</code>:</strong> Censys, Shodan, Shadowserver, GreyNoise, LeakIX, &#x26; internal inventory help assess real exposure.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> External scan data can be stale or incomplete; join with internal evidence.</td></tr><tr><td align="right">9</td><td><strong>Malicious package &#x26; supply-chain compromise</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/advisories?query=type%3Amalware">github.com/advisories?query=type%3Amalware</a>, <a href="https://github.com/ossf/malicious-packages">github.com/ossf/malicious-packages</a>, <a href="https://github.com/ossf/package-analysis">github.com/ossf/package-analysis</a>, <a href="https://security.snyk.io/">security.snyk.io</a>, <a href="https://socket.dev/blog">socket.dev/blog</a>, <a href="https://sonatype.com/resources/vulnerability-database">sonatype.com/resources/vulnerability-database</a><br><br><strong><code>Access / Cost</code>:</strong> Mixed: free public, open-source, free tiers / commercial products</td><td><strong><code>Relevance</code>:</strong> Tracks malicious package risk that may not appear as conventional CVEs.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Essential for supply-chain defense &#x26; dependency risk.</td></tr><tr><td align="right">10</td><td><strong>Detection engineering</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://codeql.github.com/">codeql.github.com</a>, <a href="https://github.com/projectdiscovery/nuclei">github.com/projectdiscovery/nuclei</a>, <a href="https://google.github.io/oss-fuzz/">google.github.io/oss-fuzz</a>, <a href="https://joern.io/">joern.io</a>, <a href="https://samate.nist.gov/SARD/">samate.nist.gov/SARD</a>, <a href="https://semgrep.dev/">semgrep.dev</a><br><br><strong><code>Access / Cost</code>:</strong> Mixed: free/open-source, free public datasets, commercial tiers for some products</td><td><strong><code>Relevance</code>:</strong> CodeQL, Semgrep, Joern, Infer, Nuclei, OSS-Fuzz, SARD, &#x26; vulnerability datasets support detection &#x26; validation.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Detection quality depends on rule precision, context, &#x26; evidence quality.</td></tr><tr><td align="right">11</td><td><strong>Threat intelligence</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://blog.google/threat-analysis-group/">blog.google/threat-analysis-group</a>, <a href="https://blog.talosintelligence.com/">blog.talosintelligence.com</a>, <a href="https://cloud.google.com/blog/topics/threat-intelligence">cloud.google.com/blog/topics/threat-intelligence</a>, <a href="https://unit42.paloaltonetworks.com/">unit42.paloaltonetworks.com</a>, <a href="https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/">www.microsoft.com/en-us/security/blog/topic/threat-intelligence</a>, <a href="https://www.rapid7.com/blog/tag/vulnerability-management/">www.rapid7.com/blog/tag/vulnerability-management</a>, <a href="https://www.ransomware.live/">www.ransomware.live</a><br><br><strong><code>Access / Cost</code>:</strong> Mostly free public blogs/research; commercial threat intel products separate</td><td><strong><code>Relevance</code>:</strong> Mandiant, Microsoft, Google TAG, Unit 42, Talos, Rapid7, ransomware &#x26; IOC feeds provide exploitation-in-the-wild context.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Research sources vary in timeliness, depth, &#x26; attribution confidence.</td></tr><tr><td align="right">12</td><td><strong>Compliance &#x26; configuration impact</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/ComplianceAsCode/content">github.com/ComplianceAsCode/content</a>, <a href="https://ncp.nist.gov/">ncp.nist.gov</a>, <a href="https://public.cyber.mil/stigs/">public.cyber.mil/stigs</a>, <a href="https://www.cisecurity.org/cis-benchmarks">www.cisecurity.org/cis-benchmarks</a>, <a href="https://www.open-scap.org/">www.open-scap.org</a><br><br><strong><code>Access / Cost</code>:</strong> Mostly free public / open-source; CIS benchmarks may require free registration &#x26; commercial tools exist</td><td><strong><code>Relevance</code>:</strong> CIS, STIG, SCAP, cloud posture, &#x26; Kubernetes benchmarks help assess environmental control weakness.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> These are not vulnerability feeds but determine practical risk &#x26; exploitability.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-g/20-20-final-structure-for-all-vulnerability-management-sources-and-exposure-listing.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
