SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started

Third-party data

Last updated: 2026-09-15

Why this page exists

SentriKat does not discover vulnerabilities. It reads what the public vulnerability databases publish, works out which of them apply to the software you actually run, and tells you which updates close the most of them.

Those databases are published by other people, some of them under licences that require credit. This page gives that credit, and it lets you check our work: a finding you can't trace back to a source is a finding you can't put in front of an auditor.

Sources

OSV Open Source Vulnerabilities, hosted by Google

Advisories for open source packages, across ecosystems

Published under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). Terms

CVE Program MITRE Corporation

CVE identifiers and records

Used under the CVE Program Terms of Use. Terms

Vulnerability records, severity scores, and the software identity dictionary

Published by a US government agency. See NVD's own terms. Terms

EPSS FIRST.org

Daily probability that a vulnerability will be exploited

Used under FIRST's terms for EPSS data. Terms

Vulnerabilities confirmed as exploited in the wild

Published by a US government agency. Terms

EUVD ENISA, European Union Agency for Cybersecurity

European vulnerability database, including exploited vulnerabilities

Published by an agency of the European Union. Terms

Which Ubuntu package versions carry a fix

Published by Canonical. Terms

Which Red Hat package versions carry a fix, in CSAF format

Published by Red Hat. Terms

Which Microsoft updates fix which vulnerabilities

Published by Microsoft. Terms

What we add, and what we don't

The sources above publish facts about software in general. SentriKat decides which of those facts apply to your installation, and that decision is ours: the match between a package you run and an identity in a public catalogue, the version comparison, and the grouping of vulnerabilities into the updates that close them.

Where a match is uncertain, SentriKat says so rather than guessing. A finding that cannot be tied to a published identity is reported as unverified, not as clean.

Corrections

If a source is credited wrongly here, or a source we use is missing, write to [email protected] and it will be fixed.