Data sources & attribution
PemSync aggregates publicly available data from the sources below, each credited per its terms of use.
PemSync does not originate vulnerability or lifecycle data — absence of data does not mean software is secure or supported. Verify critical information directly with the relevant source before making security, compliance, or purchasing decisions.
Vulnerability intelligence
| Source | Scope | Link |
|---|---|---|
| NVD (NIST) | CVE records, CVSS base scores, CPE applicability | nvd.nist.gov |
| CVE Program (cve.org) | Authoritative CVE records and lifecycle state (published/rejected/withdrawn) | cve.org |
| CISA KEV | Actively-exploited signal and remediation-due dates | cisa.gov/known-exploited-vulnerabilities-catalog |
| EPSS (FIRST.org) | Exploitation-likelihood percentile rank — how a CVE compares to all others, not a probability | first.org/epss |
Versions & OS lifecycle
| Source | Scope | Link |
|---|---|---|
| endoflife.date | OS/product release cycles and EOL dates | endoflife.date |
| SOFA (Mac Admins) | Current macOS release/build enrichment, from Apple's update catalogs | sofafeed.macadmins.io |
| Canonical | Ubuntu release lifecycle and support dates | changelogs.ubuntu.com/meta-release |
| Microsoft | Windows/Windows Server build revisions, KB numbers, patch dates, MSRC advisories | learn.microsoft.com/windows/release-health |
| Eclipse Adoptium | Eclipse Temurin (OpenJDK) release lines | adoptium.net |
| Vendor release channels | Current application versions, from each vendor's own update feed, version API, appcast or release-notes page | Each vendor's official channel |
| winget-pkgs (community) | Windows package manifests, used only where a vendor publishes no version feed of its own | github.com/microsoft/winget-pkgs |
Attribution notice
This product uses data from the NVD API but is not endorsed or certified by NVD or NIST. CVE® is a registered trademark of, and the CVE List is a product of, The MITRE Corporation, operated for the CVE Program. CISA KEV data is a U.S. Government work in the public domain. EPSS scores are provided by FIRST.org. endoflife.date data is used under its open licence. SOFA data is from sofafeed.macadmins.io. Ubuntu data is from Canonical’s public feeds. Windows/MSRC data is from Microsoft’s public pages. Package manifests are from the community-maintained winget-pkgs repository under its MIT licence. All trademarks are property of their respective owners. PemSync is not affiliated with or endorsed by any source or vendor named on this page, including NVD, NIST, the CVE Program, MITRE, CISA, FIRST, Apple, Canonical, Microsoft, Oracle, Adobe, Cisco, the Eclipse Foundation, The Document Foundation, or VideoLAN.