Ross ROSS = Recommend OSS · open-source software intelligence for agents

CVE List resource

CVE cache of the official CVE List in CVE JSON 5 format observed · 2026-08-28

github.com/CVEProject/cvelistV5 observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0.0
  • age_days: 1667
  • days_rel: 6
  • days_push: 7
  • n_releases_24m: 17487

Full methodology

Adoption not part of the score

2934 stars · 632 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

An official mirror/cache of the CVE List maintained by the CVE Program, published as CVE Records in JSON 5 format. It is updated continuously and includes a deltaLog for tracking recent record changes.

Use cases

  • download the full CVE list in JSON format
  • sync local CVE database with official records
  • track newly published CVE records daily
  • build a vulnerability lookup service
  • analyze CVE record changes over time
  • integrate CVE data into security tooling

When to choose

  • you need bulk offline access to all CVE records
  • you want the authoritative CVE JSON 5 source data
  • you need to track incremental CVE updates via deltaLog

When to avoid

  • you need a searchable CVE web API rather than raw data
  • you want curated or enriched vulnerability data beyond official records

Facets

dataset · maturity active

security vulnerability-scanning json security developer-tools apis cross-platform cve vulnerability-data json5 security-dataset mirror

1 source

Member repositories

RepositoryRoleHealth v2
CVEProject/cvelistV5main95
CVEProject/cvelistmirror10

For agents

markdown · JSON · MCP: product_card(name="CVEProject/cvelistV5")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem