Repository navigation
Release 2.1.0
News
- A new API endpoint allows sightings to be created programmatically. Using dedicated tools, we gather observations from three main sources:
- The Fediverse with FediVuln, a client to collect vulnerability-related information from the Fediverse
- MISP with VulnerabilityLookupSighting, a client that retrieves vulnerability observations from a MISP server and pushes them to a Vulnerability Lookup instance
- RSS and Atom feeds
- Combined sightings for bundles: The page displaying bundle details now shows the combined sightings for all vulnerabilities within the bundle (48610fc)
- New RSS/Atom endpoints for sightings have been added, allowing parameters such as the sighting source to be used and the id of a vulnerability. This enables users to subscribe to activity on unpublished vulnerabilities. (6020294)
- Provide the possibility to comment not yet published vulnerabilities (f88f239)
Changes
- Make drawBarChartHomePage faster (fa95945)
- Added a function in order to provide a small description about the vulnerabilities listed in the bundle page (8f04be1)
- Various enhancements to the home page and the charts based on user sightings
- Improved the API and the OpenAPI Swagger documentation
- Various improvements were made to the user interface
Fixes
- Fixed an issue in the Marshalling for the Sightings in the API (5ccdbe2)
- Fixed the title of the RSS/Atom feed (311d2c4)
- Keep non-sensitive case search even if our ids are lowercase. (9fae6ea)
Funding
The NGSOTI project is dedicated to training the next generation of Security Operation Center (SOC) operators, focusing on the human aspect of cybersecurity. It underscores the significance of providing SOC operators with the necessary skills and open-source tools to address challenges such as detection engineering, incident response, and threat intelligence analysis. Involving key partners such as CIRCL, Restena, Tenzir, and the University of Luxembourg, the project aims to establish a real operational infrastructure for practical training. This initiative integrates academic curricula with industry insights, offering hands-on experience in cyber ranges.
vulnerability-lookup is co-funded by CIRCL and by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or ECCC. Neither the European Union nor the granting authority can be held responsible for them.







