Skip to main content

CVE Program

Threat Intelligence

The CVE Program connector brings the official CVE List into Brinqa. The CVE List is published by the CVE Program in the CVEProject/cvelistV5 repository in CVE JSON 5.x format. Each record is the authoritative CVE entry as written by the assigning CVE Numbering Authority (CNA), together with the data added by Authorized Data Publishers (ADPs), such as CISA's Vulnrichment program.

The connector synchronizes:

  • CVE Records: one record per CVE, including rejected CVEs. Each record carries the CNA's description, CWE and CAPEC classifications, references, and CVSS v2.0, v3.x and v4.0 scores. It also carries CISA-ADP enrichment: SSVC decision points, Known Exploited Vulnerabilities (KEV) status, and CVSS and CWE backfill.
  • Affected Products: one record per entry of a CVE's affected-products list, with the vendor, product, package, CPEs and affected version ranges. This covers the CNA's own list and ADP additions.

This complements NVD: it carries the CNA's own affected-version ranges and CISA Vulnrichment data, which NVD does not always carry, and it includes CVEs that NVD has not yet analyzed.

Data retrieved from CVE Program​

Connector ObjectRequiredMaps to Data Model
CVE RecordYesCve Record
Affected ProductYesAffected Product

Model relationships​

note

For detailed steps on how to view the data retrieved from CVE Program in the Brinqa Platform, see How to view your data.