Content policy
Every entry should help an authorized tester make a better decision without hiding uncertainty or encouraging indiscriminate traffic.
Editorial standard
- Observed technology drives testing priority.
- Claims distinguish reachability, attacker control, impact, and evidence strength.
- Commands use explicit placeholders and state whether they are passive or active.
- Callback probes stop at confirmation and do not collect victim data.
- CVE claims identify their source, scoring system, exploitation signal, and freshness.
- Entries are deduplicated and retired when their underlying behavior is obsolete.
Public disclosure archive
- Only an explicitly public disclosure or primary advisory may enter the archive; authenticated account captures and private submissions are excluded.
- Records are link-first original editorial summaries. Upstream report bodies, HTML, Markdown, SVG, attachments, comments, and payloads are not imported or embedded.
- Every field is stored as plain structured data and context-encoded at render time. External links are HTTPS-only and isolated with
noopener noreferrer. - Severity remains exactly as reported by the public source and is labeled source-reported; vulns.co does not silently upgrade or rescore it.
- Each record keeps a public-status check date, review state, source link, bounded impact, and remediation pattern so it can be corrected or retired quickly.
Corrections and takedown
Send a source-backed correction or disclosure-status change through the contribution guide. Uncertainty is labeled instead of filled with assumptions, and a disputed record can be unpublished while it is reviewed.