Transparency

How we know

Every source we read — with polling interval, licence and the time of its last successful fetch. The timestamp comes from the database, not from this page.

Live sources (9)

These fetches run. The timestamp is the proof.

SourceTypeIntervalLast fetchLicence

The US agency CISA's catalogue of vulnerabilities proven to be under active exploitation. The least noisy source there is — and the only one that proves “under attack right now” rather than claiming it.

officialdaily16/09/2026, 06:05:171710 entriesPublic Domain (U.S. Government Work)

Security advisories from Germany's BSI as CSAF 2.0 documents, TLP:WHITE. German-language, broader than KEV, and the only source with a view of the German market.

officialdaily16/09/2026, 05:05:022649 entriesTLP:WHITE

CVSS scoring, attack vector and CPE identifiers for each CVE. It does not surface new flaws — it classifies known ones.

officialdaily12/09/2026, 07:05:053 entriesPublic Domain (U.S. Government Work)

Support and security end dates per product line. Not a vulnerability source — but a version without security updates is the flaw that never gets fixed.

communitydaily16/09/2026, 16:08:22MIT

CVE raw records straight from MITRE — often hours ahead of the NVD entry. The daily run reads the 24 hourly deltas and keeps what touches the catalogue.

officialdaily16/09/2026, 03:05:432012 entriesCVE Program Terms of Use

The same corpus as the CSAF documents, but with severity as a word, the portal ID and a one-line German summary — and as a cross-check on whether the CSAF index run is keeping up.

officialdaily16/09/2026, 03:05:05250 entriesTLP:WHITE

The handful of events per year for which Germany's BSI issues its own advisory with a criticality rating. It does not get less noisy than this in German.

officialdaily16/09/2026, 03:05:0510 entriesTLP:WHITE

The first vendor advisory page in the set — and the only source that names both affected and fixed version ranges. Exactly the detail that turns “might affect me” into “affects me”.

vendordaily16/09/2026, 03:05:07114 entries

German-language security journalism. Not proof but an early warning: what appears here is on the management's desk tomorrow.

early warningdaily16/09/2026, 03:05:0120 entries© Heise Medien — nur Titel, Link und Anriss

Lead time over the official advisory

No defensible number yet: within the last 90 days there are fewer than 10 usable pairs. A number appears here once there are enough — and not a second earlier.

For every vulnerability that shows up both here and at Germany's BSI we compare our detection time with the BSI advisory's publication date. Only pairs within 14 days of each other count — the same CVE is not yet the same event. Bulk imports are excluded. We report the median, not the mean.

In preparation (8)

None of this is built. The list is here because “and then?” would otherwise go unanswered — not as a promise.

SourceTypeIntervalLast fetchLicence

ENISA's European vulnerability database.

officialevery 60 min

Probability that a CVE will be exploited within 30 days. The number that turns 40,000 CVEs into a running order.

communitydaily

Vulnerabilities in open source packages, usually ahead of any official advisory.

communityevery 60 min

Package-precise affectedness data across all major ecosystems.

communityevery 60 min
Hersteller-PSIRT (CSAF/VEX)

Microsoft MSRC, Cisco, Fortinet, Broadcom/VMware, Red Hat, SUSE, Ubuntu, Debian, Sophos, Veeam, Palo Alto. The vendor knows first.

vendorevery 60 min
PoC- und Scanner-Signale

PoC commits on GitHub, Nuclei templates, Exploit-DB, Metasploit modules. A template that exists means somebody is already scanning.

early warningevery 30 min

Curated CVE data with its own enrichment. The fetch is built but waiting on credentials — the API requires an account.

communitydaily
CRA Single Reporting Platform

From September 2026 vendors must report actively exploited flaws EU-wide. A source that did not exist before.

officialevery 60 min

How this page is produced

  • The source registry lives in the code (`quellen-registry.ts`) and is mirrored into the database on every start.
  • Each fetch job stamps its own outcome. A run that finds nothing new counts as successful — a run that cannot reach the source does not.
  • The registry leads, not the table: a source removed from the code disappears here; one without a timestamp shows no date.

How we fetch

  • Own bot user agent with a contact address, one request per two seconds and host.
  • Conditional GET: we do not re-fetch unchanged documents.
  • No login areas, no circumvention of access controls.
  • We store metadata and link to the original — never vendor full text.

Back to vulnerabilities