VulnScope — last updated 20 July 2026
Without prior written permission:
The claim covers this particular expression: the source code, interface design, wording, the business-risk scoring model and its weightings, the curated vulnerability catalogue, and the framework crosswalk mappings.
It does not claim ownership of the public standards and data VulnScope builds on, which remain the work of their respective owners and are used here as published — CVE records (CVE Program / MITRE), NVD analysis and CPE data (NIST), the Known Exploited Vulnerabilities catalogue and the SSVC decision model (CISA, with Carnegie Mellon SEI), EPSS scores (FIRST.org), product lifecycle data (endoflife.date), the OWASP Top 10 (OWASP Foundation), PCI DSS (PCI SSC), and the HIPAA Security Rule (U.S. HHS).
Nothing here prevents anyone from independently building their own tool on those same public standards. Copyright protects an implementation, not an idea.
The backend proxy sees only what is needed to fetch public vulnerability data — CVE identifiers, product keywords and CPE strings — which it forwards to NVD, the CVE Program, FIRST.org and endoflife.date, caching responses briefly to stay within upstream rate limits. It does not receive your asset names, business-context selections, or any other inventory field.
No accounts, no advertising, no analytics or tracking cookies are set by VulnScope.
VulnScope is provided “as is”, without warranty of any kind, express or implied. It is a decision-support aid: its scoring, SSVC decisions and compliance mappings are advisory and must not be relied upon as the sole basis for a security decision.
Some mappings are documented approximations rather than authoritative crosswalks. The CWE→OWASP and OWASP→PCI/HIPAA tables are best-fit; the business-risk weights are transparent hand-tuned heuristics, itemised in the interface so you can judge them; the SSVC decision table is CISA's published v1.0 reproduced verbatim, while the derivation of its four inputs is VulnScope's own automation. Upstream data may be incomplete — a CVE awaiting NVD analysis carries no CPE or CVSS data, which VulnScope labels rather than hides.
Always verify against the vendor advisory before acting.
VulnScope is offered free of charge with no service-level commitment. It may be changed, rate-limited or withdrawn at any time. Upstream sources impose their own rate limits, which can cause searches to fail temporarily.
Permission requests, licensing enquiries and infringement reports: yasheshdshah@gmail.com