Authority and lineage

Sources

CASCA keeps transport, authorship, upstream origin, independence, rights, and freshness distinct. A provider count is never an independent-origin count.

Declared Public Core

CVE Program cvelistV5, NVD historical/selective enrichment, CISA KEV, and one exact dated FIRST EPSS observation. Broader GROUP 1 coverage is explicitly deferred.

Registry public-core-20260719.1

CVE

CVE Program cvelistV5

core identity

CVE is a trademark of The MITRE Corporation. CVE records are used under the CVE Program Terms of Use; CASCA is not endorsed by the CVE Program.

Official rights / terms ↗Staleness warning after 3 hours without an eligible observation.
NVD

NIST National Vulnerability Database

historical core selective current enrichment

This product uses the NVD but is not endorsed or certified by the NVD.

Official rights / terms ↗Staleness warning after 6 hours without an eligible observation.
KEV

CISA Known Exploited Vulnerabilities Catalog

authoritative signal

Known Exploited Vulnerabilities catalog data is attributed to CISA; CASCA is not endorsed by CISA.

Official rights / terms ↗Staleness warning after 24 hours without an eligible observation.
EPSS

FIRST Exploit Prediction Scoring System

probabilistic enrichment

EPSS probabilities and percentiles are attributed to FIRST; they are estimates, not exploitation predictions for an individual environment.

Official rights / terms ↗Staleness warning after 36 hours without an eligible observation.

Interpretation rules