Data sources
Where the data comes from
Every Stackbyte API is built on public data from official publishers: open data portals, government registers and feeds published for reuse. Each page below records the licence we rely on, how often the data changes and what it does not cover. Every API response names its sources in meta.sources.
In use
- National Vulnerability Database (NVD)NIST's database of published CVEs with CVSS scores, CWE classes and references.In use by CVE Triage
- FIRST Exploit Prediction Scoring System (EPSS)A daily probability that a CVE will be exploited in the next 30 days.In use by CVE Triage
- CISA Known Exploited Vulnerabilities (KEV) catalogueCISA's list of vulnerabilities known to be exploited in the wild.In use by CVE Triage
Planned
- OSV.dev open source vulnerability databaseOpen source package vulnerabilities across npm, PyPI, Go, Maven and more.Planned for Package Risk
- deps.dev (Open Source Insights)Dependency, licence, version and project health data for open source packages.Planned for Package Risk
- OFAC Specially Designated Nationals listThe US Treasury's list of sanctioned people, entities, vessels and aircraft.Planned for Sanctions Screen
- EU Safety Gate rapid alert systemThe European Commission's weekly alerts on dangerous non-food products.Planned for Product Recalls
- Dubai Pulse DED licence masterBusiness licences for mainland Dubai from the Department of Economy and Tourism.Planned for UAE Company Verify
How we decide a feed is safe to build on is explained in how we check a data feed. Last checked: 25 September 2026 by Stackbyte Engineering.