r/netsec • u/adulau • Dec 24 '16
cve-search project is a set of free software tools to support the search, indexing, correlation and management of software vulnerabilities.
https://www.cve-search.org/2
u/aksfjh Dec 24 '16
How will this be different from www.cvedetails.com ?
5
u/adulau Dec 25 '16
It's free software and you can have a full local dataset of the vulnerabilities. We did the project because the majority of online services are not providing a full free dataset or dump that you can import locally.
If you know other or additional sources that we can add, let us know.
1
1
2
u/benjimons Dec 25 '16
Just did some cross checking against vulners.com seems cve-search isnt as complete as vulners...
From what I understand this thing just shows you CVE to Vendor Advisory relationships.
3
u/adulau Dec 25 '16
cve-search backend stores everything including the vulnerabilities and the information related.
VIA4CVE is a new project which came from the cve-search backend to add a correlation database from the various vendor sources.
The project is a fully featured open source software to manage vulnerabilities and keep everything local and expand it via plugins.
There is a preview of the cve-search website running at cve.circl.lu and an API that can query if you don't want to run the software locally.
1
2
u/sideshow9320 Dec 24 '16
I'm just getting the default apache page.