Terms
What is sold
A subscription to CVE: the records as they stand rather than 30 days behind, the change feeds, the API and export.
Every CVE in CISA KEV. Red Hat since 2025-01-01, NVD since 2026-08-01, GitHub since 2026-09-01. Every Exploit-DB entry and Metasploit exploit module naming a CVE.
Not included: Vulnerabilities with no CVE number. Ubuntu, whose list endpoint answers 20 records in thirty seconds and cannot be paged at a useful rate.
What is not promised
No availability guarantee, and no undertaking about how fast a change at a publisher reaches this workspace beyond what the tracker states and shows. Every source is a third party and may change or stop without notice; where one does, the overview says so.
The data is what publishers said. It is not advice, and nothing here decides which of two publishers is right.
Money
Monthly, in advance, cancellable at any time and effective at the end of the paid period. No refund for a part-used month. Prices include VAT where it applies.
What happens when you stop
Access to current claims, feeds, the API and export ends. Anything already exported stays yours; there is no recall.
Your data
An address and, if you make them, API keys. No password is stored because none is asked for. The address is used to sign you in and to tell you about your subscription, and is deleted with the account on request.
Third-party licences
Each source carries its own terms and is named on the overview. Nothing here relicenses what a publisher wrote.
Operated by hello@zetlyn.com.