Primary sources connect this project to an EU CSIRT as developer or lead.
At a glance
Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted / Public service
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led
What the sources establish
Origin note
The upstream README identifies CIRCL, Computer Incident Response Center Luxembourg, and named project contributors as copyright holders.
Reported capabilities
Combines vulnerability feeds with comments, bundles and sightings.
Provides a lookup API and coordinated-disclosure workflows.
Scope and limits
A vulnerability intelligence and disclosure platform; it does not scan assets to establish whether they are vulnerable.
Inspect the research evidence 5 source observations
identity / capabilities / deployment
Upstream documentation describes correlate vulnerability records across sources, track sightings and support advisory publication and coordinated vulnerability disclosure. It documents local installation.
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Documented EU funding
Digital Europe Programme (DEP) · Next Generation Security Operator Training Infrastructure (NGSOTI)
Reference: 101127921
Vulnerability-Lookup acknowledges NGSOTI co-funding. The action runs from January 2024 to December 2026; the acknowledgement does not specify an amount for this tool.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Put the tool in context.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.