products

Supported Products

The API covers 356 CVE-backed infrastructure products. This page documents 77 featured products with deployment context, version format notes, and notable CVE history. View all API slugs.

Pass the exact slug as the product parameter. Product names are normalized to lowercase with spaces replaced by underscores, so Apache Log4j and log4j resolve to the same record.

Databases
Apache Cassandracassandra

Distributed wide-column store from the ASF. CVE history includes serious issues in optional features (e.g. UDF execution). Keyword uses the full phrase "Apache Cassandra" to limit noise.

High-throughput writes, time series at scale, multi-region clusters

Apache CouchDBcouchdb

Document database with replication. Includes critical historical RCEs (e.g. CVE-2022-24706, KEV). Tracked as apache:couchdb.

Offline-first apps, sync-heavy workloads

Apache Derbyapache_derby

Apache's embedded Java relational database (JDBC). NVD tracks it as apache:derby with a modest but usable CVE history for server-side SQL and network exposure scenarios.

Embedded databases, Java tooling, test fixtures

Couchbase Servercouchbase

Distributed document database with search and analytics. Tracked as couchbase:couchbase_server in NVD with substantive CVE ranges.

Mobile sync backends, session stores, personalization

Elasticsearchelasticsearch

Elastic's search and analytics engine. Standard semver in NVD under elastic:elasticsearch.

Search, log aggregation, observability stacks

MariaDBmariadb

Community fork of MySQL. Single NVD namespace mariadb:mariadb with strong CVE coverage and semver-style versions.

MySQL-compatible deployments, managed databases

Microsoft SQL Servermssql

Enterprise RDBMS from Microsoft. NVD commonly uses dotted build numbers (e.g. 15.0.x) rather than marketing years.

Enterprise apps, .NET stacks, Azure SQL siblings

MongoDBmongodb

Document-oriented database. MongoDB is a CNA; NVD entries often include explicit CPE ranges.

Application data, analytics, AI/ML pipelines

MySQLmysql

Oracle's open-source RDBMS. NVD merges pre- and post-acquisition vendor namespaces (mysql:mysql and oracle:mysql) for complete historical coverage.

LAMP/LEMP stacks, SaaS backends, managed MySQL

Oracle Databaseoracle_db

Oracle's flagship RDBMS. NVD uses numeric release trains (e.g. 19.x, 21.x), not marketing labels like 19c.

ERP, finance, large packaged applications

PostgreSQLpostgresql

The PostgreSQL open-source relational database. Coverage includes server-side vulnerabilities and privilege bypass issues in the query engine.

Application databases, analytics workloads

Redisredis

In-memory data structure store. CVE records are merged across two NVD vendor namespaces reflecting the 2021 vendor name change from redislabs to redis.

Caching layers, session stores, message queues

SQLitesqlite

Embedded SQL engine. CVE history is thinner than client-server databases but includes real memory-safety issues; tracked as sqlite:sqlite.

Mobile apps, browsers, embedded devices, desktop software

Web servers & proxies
Apache HTTP Serverapache_httpd

The Apache HTTP Server Project's web server, tracked as apache:http_server in NVD. Coverage includes module-specific vulnerabilities such as mod_proxy and mod_cgi.

Web servers, shared hosting infrastructure

Caddycaddy

Go-based HTTP server with automatic HTTPS. Tracked as caddyserver:caddy in NVD. Newer project; added after passing eligibility checks.

Developer environments, reverse proxies, AI deployment endpoints

HAProxyhaproxy

High-availability load balancer and TCP/HTTP proxy. HAProxy is its own CNA and self-publishes CVEs, producing high-quality NVD records. CVE history concentrates in HTTP header parsing and request smuggling.

Load balancers, API gateways, high-availability frontends

NGINXnginx

HTTP server and reverse proxy. CVE coverage spans pre- and post-F5 acquisition records, merged across two NVD vendor namespaces.

Web servers, load balancers, API gateways

Squidsquid

Caching proxy for HTTP, HTTPS, and FTP. Tracked as squid-cache:squid in NVD with an extensive CVE history in HTTP request parsing and authentication handling.

Forward proxies, content caching, network security layers

Traefiktraefik

Cloud-native reverse proxy and ingress controller for Kubernetes and container environments. Tracked as traefik:traefik in NVD.

Kubernetes ingress, microservice routing, AI model serving endpoints

Varnish Cachevarnish

HTTP accelerator for content-heavy dynamic websites. NVD uses two CPE namespaces (varnish-cache:varnish and varnish_cache_project:varnish_cache); both are queried and merged.

CDN edge caching, high-traffic web frontends

Messaging & streaming
Containers & orchestration
Service mesh & networking
Observability & monitoring
Grafanagrafana

Metrics, logs, and traces visualization platform. Tracked as grafana:grafana in NVD with deep CVE history spanning authentication bypass, SSRF, path traversal, and plugin vulnerabilities.

Dashboards, SRE tooling, full-stack observability, incident response

Kibanakibana

Elastic stack visualization layer for Elasticsearch data. Tracked as elastic:kibana in NVD with path traversal, SSRF, and stored XSS CVE history. Pairs with Elasticsearch and Logstash coverage.

Elastic stack dashboards, log analytics, security operations centers

Logstashlogstash

Elastic stack log ingestion and routing pipeline. Tracked as elastic:logstash in NVD. Often deployed with broad network access and credentials to multiple data sources.

Log pipelines, Elastic stack ingestion, SIEM data routing

Zabbixzabbix

Enterprise monitoring platform with deep NVD CVE history. CVE-2022-23134 (CVSS 9.8, CISA KEV) is an authentication bypass in the setup wizard. Zabbix agents run on every monitored host.

Enterprise monitoring, agent-based infrastructure, government and regulated environments

Fluentdfluentd

Log collection and forwarding daemon, widely used as the default log aggregator in Kubernetes. Tracked as fluentd:fluentd in NVD with HTTP parsing and plugin CVE history.

Kubernetes log aggregation, CNCF observability stacks, multi-source log routing

Oracle Enterprise Manager Grid Controloracle_enterprise_manager_grid_control

Oracle's centralized infrastructure and database monitoring platform. Tracked as oracle:enterprise_manager_grid_control in NVD with CVE history spanning authenticated remote code execution and privilege escalation in management console components.

Oracle database fleet management, enterprise infrastructure monitoring, Oracle application lifecycle

Infrastructure & runtimes
Apache Axisapache_axis

Java SOAP and JAX-WS web services framework from the Apache Software Foundation, tracked as apache:axis in NVD. The 1.x line is end-of-life with no patch for CVE-2023-40743 (CVSS 9.8), which enables unauthenticated remote class loading via the lookup endpoint.

Legacy SOAP integrations, enterprise Java middleware, JAX-WS web service deployments

Apache Tomcattomcat

The Apache Software Foundation servlet container for Java web applications. Tracked as apache:tomcat in NVD.

Java application servers, Spring Boot embedded servers, PaaS runtimes

Jettyjetty

Java HTTP server and servlet container maintained by the Eclipse Foundation. Historical CVEs use the legacy mortbay:jetty namespace; current CVEs use eclipse:jetty. Both are queried and merged on CVE ID.

Java application servers, embedded in Solr and Eclipse IDE

Apache Log4jlog4j

Java logging library from the Apache Software Foundation. Covers both the 1.x and 2.x release families, each tracked under separate NVD CPE namespaces.

JVM applications, enterprise middleware, Elasticsearch

Microsoft Exchange Servermicrosoft_exchange

Microsoft's on-premises mail server. Version strings using CU notation (Exchange 2019 CU14) are normalized before range comparison.

Enterprise email infrastructure, hybrid Office 365 deployments

OpenSSHopenssh

OpenBSD's SSH implementation. The portable suffix on version strings (9.2p1, 9.3p2) is stripped before comparison against NVD version ranges.

Remote administration, server fleets, network devices

VMware ESXivmware_esxi

VMware's bare-metal hypervisor, tracked as an OS-class CPE (cpe:2.3:o). Version strings using Update notation (7.0 U3) are normalized before comparison.

Virtualization hosts, private cloud infrastructure

Security tooling
CI/CD platforms
JavaScript runtimes & sandboxes
Authentication & identity
Keycloakkeycloak

Red Hat's open-source IAM platform providing SSO, OAuth2/OIDC, and user federation. Tracked as redhat:keycloak in NVD with a strong CVE history including auth bypass and redirect-URI traversal chains.

Enterprise SSO, Kubernetes service accounts, OAuth2 broker, developer portals

OpenLDAPopenldap

Widely deployed open-source LDAP implementation backing enterprise directory services. NVD namespace is openldap:openldap with a focused history of memory corruption and denial-of-service issues.

AD replacement, user directory, auth backends, enterprise identity

FreeIPAfreeipa

Red Hat's integrated identity management combining LDAP, Kerberos, DNS, and certificate management in one solution. Tracked as freeipa:freeipa in NVD.

Enterprise Linux identity, RHEL/CentOS environments, Kerberos SSO

Linux-PAMlinux_pam

Pluggable Authentication Modules for Linux — the authentication layer for login, sudo, and SSH on virtually every Linux system. Tracked as linux-pam:linux-pam in NVD.

Login daemons, sudo, PAM-aware services, authentication policy enforcement

Sambasamba

The open-source implementation of Windows file sharing and Active Directory services. CVE-2017-7494 (EternalRed, CVSS 9.8, CISA KEV) and CVE-2021-44142 (heap OOB, CVSS 9.9) are canonical references. Deep NVD history.

Windows interop, AD replacement, file servers, SMB infrastructure

MIT Kerberosmit_kerberos

MIT's reference implementation of the Kerberos 5 authentication protocol. The foundational library for Kerberos-based SSO across Linux, macOS, and enterprise environments. Tracked as mit:kerberos_5 in NVD.

Enterprise SSO, GSSAPI, Kerberos realm infrastructure, FreeIPA backends

Language runtimes
Pythonpython

The CPython interpreter. NVD publishes under both python:python and python:cpython — ingestion uses the canonical python:python namespace. Deep CVE history across the 3.x line and the EOL 2.x tail.

AI/ML pipelines, API servers, scripting, data engineering, agent backends

Rubyruby

The MRI (CRuby) interpreter. Tracked as ruby-lang:ruby in NVD with a solid CVE history in HTTP client handling, URI parsing (ReDoS), and string processing.

Rails applications, gem tooling, DevOps scripting, web backends

PHPphp

The PHP interpreter. One of the deepest CVE histories of any product in the coverage set. CVE-2024-4577 (CVSS 9.8, CISA KEV) — CGI argument injection on Windows — is a canonical exploited-in-the-wild reference.

Web backends, WordPress/Laravel/Symfony applications, shared hosting

Gogo

The Go compiler and standard library. CVE history formalised since 2022 via the Go security team. CVE-2023-39325 (HTTP/2 rapid reset) is a high-profile reference. Eligibility confirmed via test_nvd.py before shipping.

Cloud-native services, CLI tooling, Kubernetes controllers, agent backends

OpenJDKopenjdk

OpenJDK tracked under oracle:openjdk in NVD. The Oracle namespace covers both Oracle JDK and OpenJDK core CVEs. Sentinel rate is monitored for Oracle-JDK-specific bleed-through.

JVM workloads, Spring Boot services, enterprise Java, Android toolchains

Rustrust

The Rust compiler and standard library. Tracked as rust-lang:rust in NVD. CVE history is smaller than other runtimes but growing as the language matures into safety-critical infrastructure.

Systems programming, Wasm runtimes, CLI tools, security-critical infrastructure

Perlperl

The Perl 5 interpreter. One of the deepest legacy CVE histories of any runtime in the coverage set. Widely deployed in ops tooling, sysadmin scripts, and enterprise backends. Tracked as perl:perl in NVD.

Legacy web backends, ops scripting, bioinformatics, sysadmin tooling

Erlang/OTPerlang

The Erlang/OTP runtime. CVE-2025-32433 (unauthenticated RCE via SSH, CVSS 10.0) is a high-profile 2025 addition. Natural pairing with RabbitMQ coverage. Tracked as erlang:erlang/otp in NVD.

RabbitMQ clusters, distributed systems, telecom infrastructure, Phoenix/Elixir backends

AI tooling
full api catalog

All 356 CVE product slugs

Every slug below resolves on GET /v1/check. Detailed docs pages exist for a subset above. Pass any slug as the product parameter.

Show all 356 product names
  • Acrobatadobe_acrobat
  • Acrobat Readeradobe_acrobat_reader
  • Acrobat Reader Dcadobe_acrobat_reader_dc
  • Adobe Airadobe_adobe_air
  • Adobe Air Sdkadobe_adobe_air_sdk
  • Airadobe_air
  • Air Sdkadobe_air_sdk
  • Coldfusionadobe_coldfusion
  • Commerceadobe_commerce
  • Experience Manager Formsadobe_experience_manager_forms
  • Flash Playeradobe_flash_player
  • Apache ActiveMQapache_activemq
  • Airflowapache_airflow
  • Apisixapache_apisix
  • Archivaapache_archiva
  • Axisapache_axis
  • Apache Derbyapache_derby
  • Flinkapache_flink
  • Apache HTTP Serverapache_httpd
  • Igniteapache_ignite
  • Apache Kafkaapache_kafka
  • Kylinapache_kylin
  • Ofbizapache_ofbiz
  • Apache Pulsarapache_pulsar
  • Shiroapache_shiro
  • Solrapache_solr
  • Sparkapache_spark
  • Strutsapache_struts
  • Supersetapache_superset
  • Icloudapple_icloud
  • Itunesapple_itunes
  • Safariapple_safari
  • Xcodeapple_xcode
  • Argo CDargo_cd
  • Cloudvision Portalarista_cloudvision_portal
  • 5Th Gen Gpu Architecture Kernel Driverarm_5th_gen_gpu_architecture_kernel_driver
  • Bifrost Gpu Kernel Driverarm_bifrost_gpu_kernel_driver
  • Valhall Gpu Kernel Driverarm_valhall_gpu_kernel_driver
  • Ghostscriptartifex_ghostscript
  • Clearpass Policy Managerarubanetworks_clearpass_policy_manager
  • Bitbucketatlassian_bitbucket
  • Confluence Data Centeratlassian_confluence_data_center
  • Confluence Serveratlassian_confluence_server
  • Crowdatlassian_crowd
  • Jira Data Centeratlassian_jira_data_center
  • Jira Serveratlassian_jira_server
  • Privileged Remote Accessbeyondtrust_privileged_remote_access
  • Remote Supportbeyondtrust_remote_support
  • Cacticacti
  • Caddycaddy
  • Calicocalico
  • Apache Cassandracassandra
  • Ciliumcilium
  • Anyconnect Secure Mobility Clientcisco_anyconnect_secure_mobility_client
  • Catalyst Sd-Wan Managercisco_catalyst_sd_wan_manager
  • Digital Media Managercisco_digital_media_manager
  • Firepower Threat Defensecisco_firepower_threat_defense
  • Identity Services Enginecisco_identity_services_engine
  • Network Services Orchestratorcisco_network_services_orchestrator
  • Prime Data Center Network Managercisco_prime_data_center_network_manager
  • Sd-Wancisco_sd_wan
  • Secure Access Control Systemcisco_secure_access_control_system
  • Secure Firewall Management Centercisco_secure_firewall_management_center
  • Unified Communications Managercisco_unified_communications_manager
  • Netscaler Gatewaycitrix_netscaler_gateway
  • Netscaler Sd-Wancitrix_netscaler_sd_wan
  • Session Recordingcitrix_session_recording
  • Commvaultcommvault
  • HashiCorp Consulconsul
  • containerdcontainerd
  • Couchbase Servercouchbase
  • Couchbase Servercouchbase_couchbase_server
  • Apache CouchDBcouchdb
  • Cpanelcpanel
  • Craft Cmscraftcms_craft_cms
  • Crushftpcrushftp
  • Recoverpoint For Virtual Machinesdell_recoverpoint_for_virtual_machines
  • Dopsoftdeltaww_dopsoft
  • Denodeno
  • Dotnetnukednnsoftware_dotnetnuke
  • Dockerdocker
  • Docker Enginedocker_engine
  • Dotcmsdotcms
  • Drupaldrupal
  • Elasticsearchelasticsearch
  • Goaheadembedthis_goahead
  • Envoy Proxyenvoy
  • Erlang/OTPerlang
  • Eximexim
  • Eyesofnetworkeyesofnetwork
  • Fluentdfluentd
  • Access Managementforgerock_access_management
  • Fortiadcfortinet_fortiadc
  • Fortianalyzerfortinet_fortianalyzer
  • Forticlientemsfortinet_forticlientems
  • Fortimailfortinet_fortimail
  • Fortimanagerfortinet_fortimanager
  • Fortiproxyfortinet_fortiproxy
  • Fortiswitchmanagerfortinet_fortiswitchmanager
  • Fortiwebfortinet_fortiweb
  • FreeIPAfreeipa
  • Freetypefreetype
  • Geoservergeoserver
  • Giteagitea
  • GitLabgitlab
  • Bashgnu_bash
  • Glibcgnu_glibc
  • GnuTLSgnu_gnutls
  • Gogo
  • Gogsgogs
  • Chromegoogle_chrome
  • Grafanagrafana
  • HAProxyhaproxy
  • HashiCorp Vaulthashicorp_vault
  • Helmhelm
  • Hermeshermes
  • Vantara Pentaho Business Analytics Serverhitachi_vantara_pentaho_business_analytics_server
  • Matrix Operating Environmenthp_matrix_operating_environment
  • Openview Network Node Managerhp_openview_network_node_manager
  • Procurve Managerhp_procurve_manager
  • System Management Homepagehp_system_management_homepage
  • Aspera Faspexibm_aspera_faspex
  • Data Risk Manageribm_data_risk_manager
  • Infosphere Biginsightsibm_infosphere_biginsights
  • Planning Analyticsibm_planning_analytics
  • Sterling B2B Integratoribm_sterling_b2b_integrator
  • WebSphere MQibm_websphere_mq
  • Openfireigniterealtime_openfire
  • Imagemagickimagemagick
  • Web Studioindusoft_web_studio
  • Bindisc_bind
  • Istioistio
  • Connect Secureivanti_connect_secure
  • Endpoint Managerivanti_endpoint_manager
  • Endpoint Manager Mobileivanti_endpoint_manager_mobile
  • Policy Secureivanti_policy_secure
  • Jenkinsjenkins
  • Script Securityjenkins_script_security
  • Teamcityjetbrains_teamcity
  • Jettyjetty
  • Virtual System Administratorkaseya_virtual_system_administrator
  • Xperiencekentico_xperience
  • Keycloakkeycloak
  • Kibanakibana
  • Kubernetes API Serverkube_apiserver
  • Kubernetes kubeletkubelet
  • Langflowlangflow
  • Liferay Portalliferay_liferay_portal
  • Linux-PAMlinux_pam
  • LiteLLMlitellm
  • Apache Log4jlog4j
  • Logstashlogstash
  • MariaDBmariadb
  • Epolicy Orchestratormcafee_epolicy_orchestrator
  • Total Protectionmcafee_total_protection
  • Metabasemetabase
  • Access Managermicrofocus_access_manager
  • .Netmicrosoft_.net
  • .Net Coremicrosoft_.net_core
  • .Net Frameworkmicrosoft_.net_framework
  • Commerce Servermicrosoft_commerce_server
  • Directxmicrosoft_directx
  • Excelmicrosoft_excel
  • Microsoft Exchange Servermicrosoft_exchange
  • Exchange Servermicrosoft_exchange_server
  • Internet Explorermicrosoft_internet_explorer
  • Internet Information Servicesmicrosoft_internet_information_services
  • Jscriptmicrosoft_jscript
  • Lyncmicrosoft_lync
  • Malware Protection Enginemicrosoft_malware_protection_engine
  • Officemicrosoft_office
  • Office Powerpointmicrosoft_office_powerpoint
  • Office Sharepoint Servermicrosoft_office_sharepoint_server
  • Office Web Appsmicrosoft_office_web_apps
  • Office Web Apps Servermicrosoft_office_web_apps_server
  • Office Web Componentsmicrosoft_office_web_components
  • Outlookmicrosoft_outlook
  • Powerpointmicrosoft_powerpoint
  • Publishermicrosoft_publisher
  • Sharepoint Enterprise Servermicrosoft_sharepoint_enterprise_server
  • Sharepoint Foundationmicrosoft_sharepoint_foundation
  • Sharepoint Servermicrosoft_sharepoint_server
  • Silverlightmicrosoft_silverlight
  • System Center Operations Managermicrosoft_system_center_operations_manager
  • Visiomicrosoft_visio
  • Xml Core Servicesmicrosoft_xml_core_services
  • MIT Kerberosmit_kerberos
  • Micollabmitel_micollab
  • Mivoice Connectmitel_mivoice_connect
  • MongoDBmongodb
  • Mosquittomosquitto
  • Lanscope Endpoint Managermotex_lanscope_endpoint_manager
  • Firefoxmozilla_firefox
  • Thunderbirdmozilla_thunderbird
  • Thunderbird Esrmozilla_thunderbird_esr
  • Microsoft SQL Servermssql
  • MySQLmysql
  • Nagiosnagios
  • Nagios Xinagios_nagios_xi
  • Active Iq Unified Managernetapp_active_iq_unified_manager
  • Oncommand Unified Managernetapp_oncommand_unified_manager
  • Oncommand Unified Manager Core Packagenetapp_oncommand_unified_manager_core_package
  • Ontap Select Deploy Administration Utilitynetapp_ontap_select_deploy_administration_utility
  • Service Processornetapp_service_processor
  • NGINXnginx
  • Node.jsnodejs
  • Proselfnorthgrid_proself
  • Octoberoctobercms_october
  • OpenJDKopenjdk
  • OpenLDAPopenldap
  • Openslpopenslp
  • OpenSSHopenssh
  • Opensslopenssl
  • Application Expressoracle_application_express
  • Business Intelligenceoracle_business_intelligence
  • Coherenceoracle_coherence
  • Commerce Guided Searchoracle_commerce_guided_search
  • Configuratororacle_configurator
  • Oracle Databaseoracle_db
  • E-Business Suiteoracle_e_business_suite
  • Enterprise Manager Grid Controloracle_enterprise_manager_grid_control
  • Fusion Middlewareoracle_fusion_middleware
  • Graalvmoracle_graalvm
  • Hospitality Opera 5oracle_hospitality_opera_5
  • Http Serveroracle_http_server
  • Identity Manageroracle_identity_manager
  • Jdkoracle_jdk
  • Jreoracle_jre
  • Jrockitoracle_jrockit
  • Peoplesoft Enterprise Peopletoolsoracle_peoplesoft_enterprise_peopletools
  • Primavera Unifieroracle_primavera_unifier
  • Weblogic Serveroracle_weblogic_server
  • Zfs Storage Appliance Kitoracle_zfs_storage_appliance_kit
  • Prtg Network Monitorpaessler_prtg_network_monitor
  • Expeditionpaloaltonetworks_expedition
  • Papercut Mfpapercut_papercut_mf
  • Papercut Ngpapercut_papercut_ng
  • Perlperl
  • Intellispace Portalphilips_intellispace_portal
  • PHPphp
  • Phpmyadminphpmyadmin
  • Playsmsplaysms
  • PostgreSQLpostgresql
  • Loadmasterprogress_loadmaster
  • Moveit Transferprogress_moveit_transfer
  • Sitefinityprogress_sitefinity
  • Whatsup Goldprogress_whatsup_gold
  • Projectsendprojectsend
  • Flexplmptc_flexplm
  • Pulse Connect Securepulsesecure_pulse_connect_secure
  • Pulse Policy Securepulsesecure_pulse_policy_secure
  • Pythonpython
  • Qlik Senseqlik_qlik_sense
  • Photo Stationqnap_photo_station
  • Kace System Management Appliancequest_kace_system_management_appliance
  • Kace Systems Management Appliancequest_kace_systems_management_appliance
  • RabbitMQrabbitmq
  • Unrarrarlab_unrar
  • Winrarrarlab_winrar
  • Rconfigrconfig
  • Cloudformsredhat_cloudforms
  • Icedtea6redhat_icedtea6
  • Jboss Enterprise Application Platformredhat_jboss_enterprise_application_platform
  • Openshift Container Platformredhat_openshift_container_platform
  • Richfacesredhat_richfaces
  • Satelliteredhat_satellite
  • Subscription Asset Managerredhat_subscription_asset_manager
  • Redisredis
  • Factorytalk Services Platformrockwellautomation_factorytalk_services_platform
  • Webmailroundcube_webmail
  • Rubyruby
  • Railsrubyonrails_rails
  • runcrunc
  • Rustrust
  • Saltsaltstack_salt
  • Sambasamba
  • Magicinfo 9 Serversamsung_magicinfo_9_server
  • Freepbxsangoma_freepbx
  • Commerce Cloudsap_commerce_cloud
  • Content Serversap_content_server
  • Netweaversap_netweaver
  • Netweaver Application Server Javasap_netweaver_application_server_java
  • Solution Managersap_solution_manager
  • Scadabrscadabr
  • Sl1sciencelogic_sl1
  • Servicenowservicenow
  • Sinec Inssiemens_sinec_ins
  • Experience Managersitecore_experience_manager
  • Experience Platformsitecore_experience_platform
  • Smartermailsmartertools_smartermail
  • Orion Platformsolarwinds_orion_platform
  • Serv-Usolarwinds_serv_u
  • Web Help Desksolarwinds_web_help_desk
  • Nexus Repository Managersonatype_nexus_repository_manager
  • Web Appliancesophos_web_appliance
  • SQLitesqlite
  • Squidsquid
  • Sugarcrmsugarcrm
  • Jresun_jre
  • Studio Onsitesuse_studio_onsite
  • Zimbra Collaboration Suitesynacor_zimbra_collaboration_suite
  • Sysaidsysaid
  • Systeminformationsysteminformation
  • Teamviewerteamviewer
  • Tekton Pipelinestekton
  • Fuel Cmsthedaylightstudio_fuel_cms
  • Thinkphpthinkphp
  • Jasperreports Librarytibco_jasperreports_library
  • Jasperreports Servertibco_jasperreports_server
  • Apache Tomcattomcat
  • Tortorproject_tor
  • Traefiktraefik
  • Apex Centraltrendmicro_apex_central
  • Apex Onetrendmicro_apex_one
  • Officescantrendmicro_officescan
  • Worry-Free Business Securitytrendmicro_worry_free_business_security
  • Vtscadatrihedral_vtscada
  • Varnish Cachevarnish
  • Vbulletinvbulletin
  • Next.Jsvercel_next.js
  • Backup Execveritas_backup_exec
  • Vitevitejs_vite
  • vm2vm2
  • Aria Operationsvmware_aria_operations
  • VMware ESXivmware_esxi
  • Fusionvmware_fusion
  • Identity Managervmware_identity_manager
  • Spring Cloud Configvmware_spring_cloud_config
  • Spring Cloud Functionvmware_spring_cloud_function
  • Spring Frameworkvmware_spring_framework
  • Vcenter Servervmware_vcenter_server
  • Vrealize Automationvmware_vrealize_automation
  • Vrealize Operations Managervmware_vrealize_operations_manager
  • Workspace One Accessvmware_workspace_one_access
  • Wazuhwazuh
  • Webkitgtkwebkitgtk
  • Webminwebmin
  • Libwebpwebmproject_libwebp
  • Wing Ftp Serverwftpserver_wing_ftp_server
  • Whatsappwhatsapp
  • Whatsapp Businesswhatsapp_whatsapp_business
  • Xpdfxpdfreader_xpdf
  • Xstreamxstream
  • Xwikixwiki
  • Yiiyiiframework_yii
  • Zabbixzabbix
  • ZeroMQzeromq
  • Collaborationzimbra_collaboration
  • Zk Frameworkzkoss_zk_framework
  • Biotimezkteco_biotime
  • Manageengine Access Manager Pluszohocorp_manageengine_access_manager_plus
  • Manageengine Adaudit Pluszohocorp_manageengine_adaudit_plus
  • Manageengine Adselfservice Pluszohocorp_manageengine_adselfservice_plus
  • Manageengine Desktop Centralzohocorp_manageengine_desktop_central
  • Manageengine Servicedesk Pluszohocorp_manageengine_servicedesk_plus
  • Manageengine Servicedesk Plus Mspzohocorp_manageengine_servicedesk_plus_msp

Supply chain monitoring: In addition to 356 CVE-covered infrastructure products, Attestd monitors 27,459 PyPI and 237,601 npm packages for malicious publishes and OSV advisories. See the full list and details.

eligibility criteria

How products are selected

Not every software product produces reliable output from a CPE-based synthesis pipeline. A product must meet all three criteria before it is added:

01

Sentinel rate below 50%

A sentinel range is an NVD record that names a product as affected but omits version data. High sentinel rates mean the pipeline cannot determine which versions are affected, producing unreliable results. Products with ecosystem-level CVE noise (CMSes, plugin platforms) typically fail this criterion.

02

At least 10 CVEs with valid version ranges

Products with fewer than 10 usable records produce output that may reflect NVD coverage gaps rather than actual security posture. Thin datasets do not provide enough signal for accurate risk classification.

03

Complete CPE namespace coverage

When a vendor is acquired or renames itself, NVD may maintain two separate CPE namespaces for the same product. Both must be queried and merged to avoid silently missing historical CVEs. nginx, log4j, Redis, and MySQL each required this treatment.

coverage requests

Request a product

Coverage expands based on demand. Email [email protected] with the product name and your use case. Products with structural NVD data quality problems (high sentinel rates, inconsistent CPE namespaces) cannot be added until those issues are resolved upstream.