SEC
Security advisories and identifiers. Agent asks: Is this CVE exploited in the wild; does this pattern have KEV or GHSA precedent. 12 live of 25 entries.
One CISA corpus: advisories and the Known Exploited Vulnerabilities catalog together. An agent answering 'is this CVE exploited in the wild, and what do the mitigations say' querie...
an agent triaging an active campaign queries this for the alert's IOCs, required actions and mitigations
an agent triaging findings queries this for whether a CVE is known-exploited in the wild, with ransomware-use and due-date fields
an agent assessing a CVE queries this for the authoritative record: CVSS, affected versions, CPE, references and ADP history in full
an agent mapping a CVE to public PoCs queries this for the cross-reference: PoC repo URLs per CVE id plus the trickest/wordlist metadata
year backfill slice of the exploit-PoC set: 2023 PoC repositories at pinned shas
year backfill slice of the exploit-PoC set: 2024 PoC repositories at pinned shas
year backfill slice of the exploit-PoC set: 2025 PoC repositories at pinned shas
an agent triaging a fresh CVE queries this for runnable 2026 PoC repositories: exploit source, affected product, and the fix commit together
an agent matching an exploit to its target queries this for the full Exploit-DB record and exploit source
an agent prioritising remediation queries this for a CVE's EPSS score and percentile to rank patch order
an agent auditing dependencies across ecosystems queries this for GitHub-reviewed advisories with CVSS and patched ranges
an agent reviewing Go modules queries this for Go-team-curated advisories with symbols and fixed versions
an agent writing or reviewing detections queries this for technique ids, tactics, detection data-sources and procedure examples
an agent reasoning about attack surface queries this for attack-pattern enumerations with prerequisites and mitigations
an agent classifying a finding queries this for the CWE definition, its parents/children and detection notes
an agent designing a control or wipe procedure queries this for what SP 800-53/61/63/88/207 actually require, clause-level
an agent hardening infrastructure queries this for NSA/CISA joint guidance specifics (MTIG, memory-safe roadmaps, KPMs)
an agent pinning dependencies queries this for affected-version truth across Go/PyPI/npm, resolved to one record per vulnerability
an agent reviewing an application's security posture queries this for the ASVS requirement and its verification level
an agent implementing an auth/upload/crypto feature queries this for the concrete cheatsheet: header lists, code shapes, test ideas
an agent planning a web test pass queries this for test categories, procedures and expected results
an agent reviewing Python dependency trees queries this for PYSEC advisory records with fixed versions
an agent reviewing Rust crate dependencies queries this for vulnerable crate versions, affected functions (271 RustSec advisories carry symbol lists), and patched releases: one tex...
an agent confirming a vulnerability is actually fixed queries this for the fixing commit references (SAP project-kb cvefixcommit)