Data sources
Every dataset behind this archive, in one place — what it is, how much of it there is, and how fresh it is. Click a card to browse that section directly. Whole archive last rebuilt today (2026-08-31).
Bug bounty & audit disclosures
6 platforms — HackerOne, Bugcrowd, Code4rena, Immunefi, Intigriti, YesWeHack. Factual metadata + short excerpt + link to the canonical source, never the full report body.
CVE intelligence — NVD + CISA KEV
Per-CVE description, CVSS vector, dates, references, and affected products (CPE) from NVD, merged with CISA's Known Exploited Vulnerabilities catalogue (due date, vendor/product, ransomware use).
Knowledge base
OWASP WSTG, OWASP Cheat Sheet Series, OWASP API Security Top 10, PayloadsAllTheThings, HowToHunt, the Bug Bounty Cheatsheet, and the CISA KEV feed digest — full text, permissively licensed.
CWE — Common Weakness Enumeration
The full MITRE weakness catalog, not just the subset already referenced by an archive CVE. Every CWE badge elsewhere in the archive links here.
CAPEC — attack patterns
The full MITRE attack pattern catalog, each linked to the CWE(s) it exploits. Execution-flow / step-by-step methodology intentionally excluded.
Open-source package vulnerabilities
OSV.dev (8 ecosystems: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, NuGet) + GitHub's github-reviewed advisories, ingested independently — overlaps are cross-referenced, not merged.