Back to About

Data sources & attribution

PemSync aggregates publicly available data from the sources below, each credited per its terms of use.

PemSync does not originate vulnerability or lifecycle data — absence of data does not mean software is secure or supported. Verify critical information directly with the relevant source before making security, compliance, or purchasing decisions.

Vulnerability intelligence

SourceScopeLink
NVD (NIST)CVE records, CVSS base scores, CPE applicabilitynvd.nist.gov
CVE Program (cve.org)Authoritative CVE records and lifecycle state (published/rejected/withdrawn)cve.org
CISA KEVActively-exploited signal and remediation-due datescisa.gov/known-exploited-vulnerabilities-catalog
EPSS (FIRST.org)Exploitation-likelihood percentilesfirst.org/epss

Versions & OS lifecycle

SourceScopeLink
endoflife.dateOS/product release cycles and EOL datesendoflife.date
SOFA (Mac Admins)Current macOS release/build enrichment, from Apple's update catalogssofafeed.macadmins.io
CanonicalUbuntu release lifecycle and support dateschangelogs.ubuntu.com/meta-release
MicrosoftWindows/Windows Server build revisions, KB numbers, patch dates, MSRC advisorieslearn.microsoft.com/windows/release-health
Vendor release channelsCurrent application versions (e.g. Mozilla, Chrome release blogs)Each vendor's official channel

Attribution notice

This product uses data from the NVD API but is not endorsed or certified by NVD or NIST. CVE® is a registered trademark of, and the CVE List is a product of, The MITRE Corporation, operated for the CVE Program. CISA KEV data is a U.S. Government work in the public domain. EPSS scores are provided by FIRST.org. endoflife.date data is used under its open licence. SOFA data is from sofafeed.macadmins.io. Ubuntu data is from Canonical’s public feeds. Windows/MSRC data is from Microsoft’s public pages. All trademarks are property of their respective owners. PemSync is not affiliated with or endorsed by NVD, NIST, the CVE Program, MITRE, CISA, FIRST, Apple, Canonical, or Microsoft.