Vulnerability and patch data
The factual backbone of the trackers and detail pages: what shipped, what is exploited, and how severe it is.
Microsoft Security Response Center (MSRC)
Monthly security release data from the Security Update Guide's public CVRF API: CVEs, KBs, products, and Severity, reproduced as Microsoft publishes them.
Pulled from Microsoft's public programmatic API and always linked back to MSRC.Microsoft Support KB articles
The official per-update support articles. Our KB pages quote each update's Known issues section, attributed and linked to the article; excerpts only, never the full body.
Quoted with attribution and a link on every use; verify against the article before acting.CISA Known Exploited Vulnerabilities (KEV)
The exploited-in-the-wild signal across the site: KEV listings, due dates, and required actions, quoted verbatim and attributed.
Used under the KEV catalog's free-use license, with attribution to CISA. CISA does not endorse this site.FIRST.org EPSS
Exploit Prediction Scoring System probabilities, the "how likely is this to be exploited" axis in our rankings.
EPSS scores are provided freely by FIRST.org; we cite EPSS wherever the scores appear.Federal Register and acquisition.gov
Federal rule-making for the federal page's CMMC and rule-making watch, with CMMC as its pinned lane: titles, links, dates, document types and agency names only, never document text.
United States federal government works, public domain (17 U.S.C. 105); read through the public Federal Register API and the acquisition.gov RSS feed.regulations.gov
Federal dockets and public comments for the CMMC lane of the federal page's rule-making watch: document titles, identifiers, dates and links only, never the text of a document or a comment.
Docket records are United States federal government works, public domain (17 U.S.C. 105). A public comment is written by its author rather than by the government, so we index the title and link and never store comment text. Read through the public regulations.gov API v4 with a free api.data.gov key.NIST National Vulnerability Database (NVD)
CVSS scores and vectors for enrichment across the CVE pages and trackers, and discovery of newly published Critical and High severity CVEs from every vendor.
This product uses the NVD API but is not endorsed or certified by the NVD.The CVE Program (MITRE)
The CVE identifiers that everything else keys on.
CVE is a registered mark of The MITRE Corporation; IDs are used per the CVE Terms of Use.CIRCL Vulnerability-Lookup
Open CVSS and vulnerability metadata from the Computer Incident Response Center Luxembourg, our fallback enrichment path.
Open data, gratefully used with attribution.OSV.dev
Open-source vulnerability data behind the open-source fixes tracker.
Open API; underlying advisories carry their own open licenses, linked per item.GitHub Advisory Database
Reviewed open-source security advisories.
Licensed by GitHub under Creative Commons Attribution 4.0.Microsoft documentation repositories
Commit metadata (the message, date, author, and link) behind the Microsoft docs tracker: Entra ID, Intune, Defender, the Graph API, and Microsoft's support articles. No article text is copied.
Public repositories published by Microsoft; documentation content is licensed CC BY 4.0 and we take metadata only, read through the GitHub API.VulnCheck KEV
Community exploitation intelligence that widens the exploited-CVE picture beyond the CISA catalog.
Used with a VulnCheck community license, with attribution to VulnCheck.ENISA EU Vulnerability Database (EUVD)
The European Union's vulnerability database, a cross-check and enrichment source.
Public EU service, used with attribution to ENISA.endoflife.date
End-of-support dates behind the end-of-life tracker.
A community open-source project; data used with thanks and linkback.Government and regional advisories
The advisory lanes on the regional security pages: headlines, links, and dates only, with every item pointing at the issuing agency.
CISA (United States)
Cybersecurity advisories and alerts for the US federal lane.
US government work, used with attribution. CISA does not endorse this site.NCSC (United Kingdom)
Guidance and advisories for the UK lane.
Contains public sector information licensed under the Open Government Licence v3.0.ACSC (Australia)
Alerts and advisories for the Australia lane, including Essential Eight guidance.
Australian Government material used under Creative Commons Attribution 4.0.Security press and research
The analyst and press coverage on the Patch Tuesday page, the trackers, and the per-CVE article links. We take RSS titles, links, and dates only, never the article body, and every citation sends the reader to the original. Thank you for the reporting.
Microsoft Security Blog and MSRC Blog
Microsoft's own analysis and release commentary.
Zero Day Initiative
Trend Micro ZDI's Patch Tuesday analysis and advisories.
BleepingComputer
Breaking coverage of patches, exploits, and incidents.
Dark Reading
Security news and analysis.
SANS Internet Storm Center
Daily diaries and Patch Tuesday breakdowns.
Krebs on Security
Investigative security journalism.
Cisco Talos
Threat research and Patch Tuesday coverage.
Tenable
Vulnerability analysis and Patch Tuesday reviews.
Rapid7
Vulnerability research and patch analysis.
CrowdStrike
Threat intelligence and patch commentary.
Qualys
Patch Tuesday and vulnerability research.
Help Net Security
Security news and industry coverage.
The Record
Cybersecurity news from Recorded Future News.
SecurityWeek
Security industry news and analysis.
Rod Trent, Microsoft Security Insights
Microsoft security news and commentary on Substack.
Titles, links, and dates via the public RSS feed; quotes always verbatim, attributed, and linked to Rod's post. Thank you, Rod.Breach disclosures
The Data Breaches page quotes primary sources verbatim, names and dates only plus each source's own short description, and links every item to the original record.
Have I Been Pwned
Troy Hunt's confirmed-breach catalog: what leaked and how many accounts.
Breach data licensed under Creative Commons Attribution 4.0. Thank you, Troy.SEC EDGAR
8-K "Material Cybersecurity Incidents" filings: public companies disclosing incidents in their own words.
US government public records, accessed per SEC EDGAR access guidelines.Microsoft Windows release health
Which Windows and Windows Server updates shipped and when, including the non-security preview and out-of-band packages that carry no CVEs and so appear in no security feed.
Table facts only: KB number, release date, OS build and Microsoft's own release code, plus the title of the support article where a channel is not tabulated. Article text is © Microsoft and we do not reproduce it; every KB links back to Microsoft's own page. Thank you.California Attorney General
The state's breach registry: every sample notice an organisation must send the Attorney General when a breach reaches more than 500 California residents. Confirmed and self-disclosed, and often weeks ahead of any other confirmed record.
California public records published by the Attorney General under Civil Code s. 1798.29 and s. 1798.82, taken from the registry's own full CSV export. Organisation name and dates only, every item linked back to the registry. Note the registry's own caveat: the organisation that sent a notice is not always the one that was breached.HHS Office for Civil Rights
The federal healthcare breach portal: every breach of protected health information affecting 500 or more people, reported by the organisation itself and published by HHS. Confirmed and self-reported, US healthcare only, and submissions run a few weeks behind.
United States government public records, published by the Secretary of Health and Human Services as the HITECH Act requires, taken from the portal's own CSV export. Organisation, state, dates and the portal's own categories only. The portal has no per-record web address, so every item links to the portal itself rather than to an invented URL.Schneier on Security
Commentary and analysis on security policy, AI risk, surveillance and cryptography, cited on our editorial pages and hand-written posts where the argument is worth reading rather than the advisory.
Title, date and link only, every reference linked to the original post. The blog carries no Creative Commons licence, so article text is © Bruce Schneier and we do not reproduce it; a quote is always verbatim, attributed and linked. Not a source for patch or CVE pages. Thank you.Google Project Zero
Google’s own vulnerability research team, writing up the bugs and the exploitation techniques behind them. Cited in our AI and agent security index, where the research is the point rather than any single advisory.
Title, date and link only, taken from the blog’s public feed, every reference linked to the original post. Article text is © Google and we do not reproduce it; a quote is always verbatim, attributed and linked. Not a source for patch or CVE pages. Thank you.Simon Willison
The most-cited running commentary on AI and agent security: prompt injection, tool use, and what an autonomous agent can be talked into doing. Cited in our AI and agent security index.
Title, date and link only, every reference linked to the original post. His feed carries full article text and we deliberately do not take it: the writing is his, and a quote is always verbatim, attributed and linked. Not a source for patch or CVE pages. Thank you.Brave North Technology
A Senserva partner, named in the Graph Explorer walkthrough on scoped consent where the endpoint and permission work described was done jointly with their team.
Name and link only, no content taken. Credited as a collaborator in a hand-written post, not as a data or advisory source. Not a source for patch or CVE pages. Thank you.NIST
The US National Institute of Standards and Technology’s newsroom: the standards and guidance work behind a great deal of what security teams are measured against, including the AI Risk Management Framework.
Title, date and link only, from NIST’s public news feed, every item linked to the original. Works of the United States government are not subject to domestic copyright protection (17 U.S.C. s. 105). We still link rather than reproduce. Thank you.The Register
Security-desk reporting, kept in its own "Reported, not confirmed" lane: breaches being reported now, often weeks before a confirmed record exists anywhere.
Headline, standfirst, date and link from The Register's public RSS feed, every item linked to the original article. Article text is © Situation Publishing and we do not reproduce it. Thank you.BleepingComputer
The second outlet in the "Reported, not confirmed" lane, and frequently the first anywhere to carry a breach — days before a confirmed record exists.
Headline, standfirst, date and link from BleepingComputer's public RSS feed, every item linked to the original article. Article text remains theirs and we do not reproduce it. Thank you.Community signal
The "what people are talking about" view measures where the security conversation is happening. Counts and links only; the discussion stays where it lives.
Hacker News
Discussion volume on hot CVEs and topics, via the Algolia HN Search API.
Every count links to the thread on news.ycombinator.com.Stack Exchange
Question activity on security topics, via the public Stack Exchange API.
Stack Exchange content is licensed under CC BY-SA; every item links to the original post.Google Trends
A best-effort, directional read on search interest.
Directional signal only; we publish no raw Trends data.Substack
Publishing and reader engagement on security topics: post titles and links only.
Every item links to the author's own publication.Data notice
This notice used to be repeated in full at the foot of every CVE and KB page, roughly 12,500 of them. It says the same thing in one place now, and every one of those pages links here, because a disclaimer restated 12,500 times is the pattern search engines read as scaled content. Nothing about its effect has changed.
The pages, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it. Verify against the authoritative vendor advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva End User License Agreement.
The Senserva EULA in plain language
We hold ourselves to clear terms too. Siemserva by Senserva is licensed under the Senserva End User License Agreement. These are the points users ask about most; the full Agreement is what governs, and this summary does not replace it.
Your data stays local
Siemserva runs on your own devices. Scans, analysis, and report generation happen locally, and your security assessment data is not transmitted to Senserva or any third party. Only anonymized usage statistics (feature usage, error logs, performance metrics) may be collected, never your findings or configurations.
EULA Sections 6 and 10.Read-only assessment
Siemserva reads security configuration through Microsoft Graph APIs with read-only permissions and makes no modifications to your Microsoft 365 tenant.
EULA Section 5.Licensed, not sold
Siemserva is licensed for your internal business use (including service delivery to your own customers where permitted). All intellectual property in the product remains with Senserva, LLC.
EULA Sections 1 through 3.Findings are informational
Security findings and remediation recommendations are provided for informational purposes only. They are not legal, compliance, or security advice, and Siemserva does not guarantee compliance with any framework, regulation, or standard.
EULA Section 11.Warranty terms by license
Paid Annual Licenses carry a 30-day limited warranty. Complimentary licenses are provided as is.
EULA Section 11.Third-party components keep their own licenses
Software, content, or data in Siemserva owned by others stays under its own license terms, the same respect this page shows the data sources above.
EULA Section 4.Our attribution promise
- We always quote or attribute, and we never take without credit.
- Articles and advisories appear as titles, links, and dates only; the full story is read at its source.
- Verbatim text is always quoted, attributed, and linked; required license notices stay on the page.
- Before we add a source, we check that its terms allow our use; if a source asks us to change or remove a use of its data, we do it. Reach us at info@senserva.com.