Vulnerability Notes Database

US-CERT publishes information about vulnerabilities in the Vulnerability Notes Database. Vulnerability notes include summaries, technical details, remediation information, and lists of affected vendors. Many vulnerability notes are the result of private coordination and disclosure efforts.

Recently published vulnerability notes are available via an Atom feed. US-CERT also publishes information about vulnerabilities in Current Activity and Alerts.

You can search the Vulnerability Notes Database or browse by several views. Help is available on database fields and customizing search queries. For example, you can search for specific information, such as the ten most recently updated vulnerabilities, a list of vulnerabilities that affect control systems (see also ICS-CERT), or a list of vulnerabilities discovered using the Basic Fuzzing Framework (BFF).

To communicate with us about a specific vulnerability, please send email with the appropriate VU# number(s) in the subject line. To protect sensitive, non-public vulnerability information, please encrypt to the US-CERT and CERT PGP keys.

We appreciate your comments and suggestions.