vuln-intel-reference
7 resources across 1 kinds
References
- Open ↗
CISA's authoritative catalog of vulnerabilities known to be actively exploited in the wild, used as a hard prioritization override.
- Open ↗
FIRST.org's data-driven model estimating the probability a CVE will be exploited in the wild; used to prioritize actually-exploitable vulnerabilities.
- Open ↗
NIST's national vulnerability database — CVE records with CVSS scoring and CPE mappings; a core vuln-intelligence data source.
- Open ↗Can I take over xyz?dual-use
A community-maintained catalog of services (80+) vulnerable to subdomain takeover, with per-service status, regex fingerprints for identifying vulnerable endpoints, and CI verification. Includes guidance for demonstrating takeovers responsibly.
- Open ↗chrome-mal-idspassive
A community-maintained database of malicious Chrome/Edge extension indicators of compromise, cataloguing credential stealers, browser hijackers, supply-chain compromises, and ad-fraud campaigns. It publishes in plain-text blocklist, JSON, Sigma, STIX 2.1, and MISP formats with a multi-stage verification protocol.
- Open ↗
A vulnerability-intelligence platform that aggregates CVEs from seven public sources (GHSA, NVD, CVEfixes, MegaVul, BigVul, MoreFixes, Security DPO) into a canonical schema and indexes them with vector embeddings for code-similarity, pattern-based, cross-project and natural-language search. Built on Python/FastAPI with ChromaDB and transformer embeddings, it can also generate Semgrep/CodeQL detection rules and exposes REST and CLI interfaces.
- Open ↗
Curated list of threat-intelligence resources organized into sources (100+ feeds like AbuseIPDB, GreyNoise, URLhaus), exchange formats (STIX/TAXII/MAEC), frameworks/platforms (MISP, OpenCTI, IntelMQ), analysis tools, and research/standards (MITRE ATT&CK, Diamond Model). ~10.5k stars.