Transparency
How we know
Every source we read — with polling interval, licence and the time of its last successful fetch. The timestamp comes from the database, not from this page.
Live sources (9)
These fetches run. The timestamp is the proof.
| Source | Type | Interval | Last fetch | Licence |
|---|---|---|---|---|
The US agency CISA's catalogue of vulnerabilities proven to be under active exploitation. The least noisy source there is — and the only one that proves “under attack right now” rather than claiming it. | official | daily | 16/09/2026, 06:05:171710 entries | Public Domain (U.S. Government Work) |
Security advisories from Germany's BSI as CSAF 2.0 documents, TLP:WHITE. German-language, broader than KEV, and the only source with a view of the German market. | official | daily | 16/09/2026, 05:05:022649 entries | TLP:WHITE |
CVSS scoring, attack vector and CPE identifiers for each CVE. It does not surface new flaws — it classifies known ones. | official | daily | 12/09/2026, 07:05:053 entries | Public Domain (U.S. Government Work) |
Support and security end dates per product line. Not a vulnerability source — but a version without security updates is the flaw that never gets fixed. | community | daily | 16/09/2026, 16:08:22 | MIT |
CVE raw records straight from MITRE — often hours ahead of the NVD entry. The daily run reads the 24 hourly deltas and keeps what touches the catalogue. | official | daily | 16/09/2026, 03:05:432012 entries | CVE Program Terms of Use |
The same corpus as the CSAF documents, but with severity as a word, the portal ID and a one-line German summary — and as a cross-check on whether the CSAF index run is keeping up. | official | daily | 16/09/2026, 03:05:05250 entries | TLP:WHITE |
The handful of events per year for which Germany's BSI issues its own advisory with a criticality rating. It does not get less noisy than this in German. | official | daily | 16/09/2026, 03:05:0510 entries | TLP:WHITE |
The first vendor advisory page in the set — and the only source that names both affected and fixed version ranges. Exactly the detail that turns “might affect me” into “affects me”. | vendor | daily | 16/09/2026, 03:05:07114 entries | — |
German-language security journalism. Not proof but an early warning: what appears here is on the management's desk tomorrow. | early warning | daily | 16/09/2026, 03:05:0120 entries | © Heise Medien — nur Titel, Link und Anriss |
Lead time over the official advisory
No defensible number yet: within the last 90 days there are fewer than 10 usable pairs. A number appears here once there are enough — and not a second earlier.
For every vulnerability that shows up both here and at Germany's BSI we compare our detection time with the BSI advisory's publication date. Only pairs within 14 days of each other count — the same CVE is not yet the same event. Bulk imports are excluded. We report the median, not the mean.
In preparation (8)
None of this is built. The list is here because “and then?” would otherwise go unanswered — not as a promise.
| Source | Type | Interval | Last fetch | Licence |
|---|---|---|---|---|
ENISA's European vulnerability database. | official | every 60 min | — | — |
Probability that a CVE will be exploited within 30 days. The number that turns 40,000 CVEs into a running order. | community | daily | — | — |
Vulnerabilities in open source packages, usually ahead of any official advisory. | community | every 60 min | — | — |
Package-precise affectedness data across all major ecosystems. | community | every 60 min | — | — |
Hersteller-PSIRT (CSAF/VEX) Microsoft MSRC, Cisco, Fortinet, Broadcom/VMware, Red Hat, SUSE, Ubuntu, Debian, Sophos, Veeam, Palo Alto. The vendor knows first. | vendor | every 60 min | — | — |
PoC- und Scanner-Signale PoC commits on GitHub, Nuclei templates, Exploit-DB, Metasploit modules. A template that exists means somebody is already scanning. | early warning | every 30 min | — | — |
Curated CVE data with its own enrichment. The fetch is built but waiting on credentials — the API requires an account. | community | daily | — | — |
CRA Single Reporting Platform From September 2026 vendors must report actively exploited flaws EU-wide. A source that did not exist before. | official | every 60 min | — | — |
How this page is produced
- The source registry lives in the code (`quellen-registry.ts`) and is mirrored into the database on every start.
- Each fetch job stamps its own outcome. A run that finds nothing new counts as successful — a run that cannot reach the source does not.
- The registry leads, not the table: a source removed from the code disappears here; one without a timestamp shows no date.
How we fetch
- Own bot user agent with a contact address, one request per two seconds and host.
- Conditional GET: we do not re-fetch unchanged documents.
- No login areas, no circumvention of access controls.
- We store metadata and link to the original — never vendor full text.