CVE-Compatible Products and Services (Archived)


NOTICE: The CVE Compatibility Program has been discontinued. The product listings included in this section have been moved to "archive" status.

MOVING FORWARD: Please follow these CVE Compatibility Guidelines to make your product or service "CVE Compatible."


Archived:


OFFICIALLY CVE-COMPATIBLE

Products and Services: 153
Organizations Participating: 84

The products and services listed below have achieved the final stage of the CVE Compatibility Process and are now "Officially CVE-Compatible." Each organization's product is now eligible to use the CVE-Compatible Product/Service logo, and their completed "CVE Compatibility Questionnaires" are posted here and on the Organizations Participating page as part of their product listings.

Organizations are listed alphabetically:

A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
AdventNet, Inc.

Web Site:

Quote/Declaration: AdventNet is pleased to support CVE names in the vulnerability database of the SecureCentral product line, as part of our commitment to embracing industry standards.

Name: ManageEngine Security Manager Plus
Type: Vulnerability Management Software for Windows and Linux Systems  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecureCentral PatchQuest
Type: Patch Management Software for Windows and Linux systems  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 20, 2014
Altex-Soft Date Declared: February 6, 2013

Web Sites:

(English) altx-soft.com
(Russian) altx-soft.ru
Name: Altex-Soft Ovaldb
Type: Vulnerability, Patch, and Compliance Assessment  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Nov 3, 2014
Application Security, Inc.

Web Site:

Quote/Declaration: Application Security, Inc. is committed to delivering solutions that are compatible and interoperable with the IT security environment at large. In the vulnerability management marketplace, that means speaking CVE. We've kept our SHATTER knowledgebase, the world's most comprehensive list of database vulnerabilities and misconfigurations, up-to-date with CVE references since 2004.

— Josh Shaul, CTO
Name: AppDetectivePro
Type: Database Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: DbProtect
Type: Database Intrusion Protection, Detection, and Prevention  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: TeamSHATTER.com
Type: Threat Resource Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Assuria Limited

Web Site:

Quote/Declaration: Assuria Auditor (formerly ISS System Scanner) was previously certified as ISS System Scanner. Assuria have enhanced and added functionality and features around CVE reporting in the product.

Name: Assuria Auditor
Type: Vulnerability Assessment and Remediation  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Avatares Foundation Date Declared: February 9, 2017

Web Site:

Quote/Declaration: AVATARES cyber security products and services provides seamless compatibility with new CVE ID formats.

— Walter Montes, Full Stack Dev of Avatares Foundation
Name: Pandora-CSF
Type: Vulnerability Analysis Service/Appliance  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 23, 2017
Beijing Leadsec Technology Co., Ltd. Date Declared: March 13, 2011

Web Site:

Name: Leadsec Intrusion Detection System
Type: Intrusion Detection System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Leadsec Intrusion Prevention System
Type: Intrusion Protection System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Leadsec Web Application Firewall (Leadsec WAF)
Type: Web Application Firewall  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Apr 5, 2016
Beijing Netpower Technologies Inc.

Web Site:

Quote/Declaration: Beijing Netpower Technologies Inc. is a leading network security products producer in China. We assure that our Netpower Network Vulnerability Scanner (NPNS) and Netpower Network Intrusion Detection System (NPIDS) are fully compatible with CVE standards.

Name: Netpower Network Intrusion Detection System (NPIDS)
Type: Intrusion Detection and Management  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Netpower Network Vulnerability Scanner (NPNS)
Type: Vulnerability Database and Scanner  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 26, 2015
Beijing Topsec Co., Ltd.

Web Site:

Name: TopSentry Intrusion Detection System
Type: Intrusion Detection and Management  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Topsec Intrusion Protection System (TopIDP)
Type: Intrusion Protection and Management  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Topsec Vulnerability Assessment and Management System (TopScanner)
Type: Vulnerability Assessment and Remediation System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Dec 23, 2013
Beijing Venustech Cybervision Co., Ltd.'s

Web Site:

Quote/Declaration: Beijing Venustech provides users with a series of network security products, which along with our own independent intellectual property, are compliant with the international standard, CVE. Beyond products, we deliver our customers life-cycle services including consulting, design, implementation, maintenance, and training.

— Helen Wang
Name: Cybervision Intrusion Detection System
Type: Intrusion Detection System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Cybervision Vulnerability Assessment and Mangement System
Type: Vulnerability Scanner  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Venusense Intrusion Prevention System
Type: Intrusion Prevention System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Venusense Threat Detection and Intelligent Analysis System
Type: Intrusion Detection and Intelligent Analysis  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Venusense Unified Security Gateway
Type: Unified Threats Management (UTM)  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Venusense Web Application Gateway
Type: Web Application Firewall  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Oct 20, 2015
Beyond Security Ltd.

Web Site:

Quote/Declaration: Beyond Security Ltd.'s Automated Scanning provides users with a complete picture of the security of their organization by leveraging the huge SecuriTeam.com knowledgebase. As such, we see high importance for the CVE naming scheme, which provides a global independent reference for known security vulnerabilities.

Name: AVDS
Type: Automated Vulnerabilities Scanner  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: AVDS Server
Type: Automated Vulnerabilities Scanner Platform For Service Providers  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: AVDS Services
Type: Automated Vulnerabilities Scanning Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Sep 23, 2013
Beyond Trust

Web Site:

Quote/Declaration: Beyond Trust is an innovative leader in vulnerability and security research, providing security solutions that help businesses and users protect their systems and intellectual property from compromise. eEye enables secure computing through world-renowned research and innovative technology, supplying the world's largest businesses with an integrated and research-driven vulnerability assessment, intrusion prevention, and client security solution. eEye is pleased to support the CVE Initiative and will continue to promote the standardization of the CVE naming convention and vulnerability identification.

Name: Retina Network Security Scanner
Type: Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 25, 2014
Black Box Corporation Date Declared: March 29, 2010

Web Site:

Quote/Declaration: As a global leader in data, voice and enterprise security solutions, Black Box Corporation (BBOX) fully supports the MITRE CVE® standard. We are pleased to deploy our award winning CVE-compatible Veri-NAC appliances into the market with a faster, less invasive vulnerability scanning system with direct links into the National Vulnerability Database (NVD) for a deeper understanding of common vulnerabilities and exposures as well as faster remediation.

Name: Veri-NAC Appliances
Type: Veri-NAC is a one-box vulnerability management and network access control (NAC) appliance  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Bluedon Information Security Technologies Co.,Ltd. Date Declared: May 18, 2017

Web Site:

Name: Bluedon Vulnerability Scanning System
Type: Vulnerability Scanning Tool/Hardware  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: September 14, 2017
Catbird Networks, Inc.

Web Site:

Quote/Declaration: Catbird V-Security is a comprehensive security and compliance solution for virtual and physical infrastructures, delivering best-practice security for Hypervisor, Guest VMs and Policy/Regulatory Compliance. Cross-indexing the CVE in reports we present to our partners and customers assists them in building effective security programs.

Name: Catbird vSecurity
Type: Security Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Cisco Systems, Inc.

Web Site:

Quote/Declaration: Cisco sees CVE as an important step in the collaborative efforts of the vulnerability science community. It is a tool that allows our security research and product development teams to focus on adding value for our customers. Cisco will incorporate the CVE dictionary into its products.

— Andrew Balinsky, Cisco Secure Encyclopedia Project Manager
Name: Cisco Security IntelliShield Alert Manager Service
Type: Security Intelligence Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 28, 2014
Cr0security Date Declared: October 1, 2013

Web Site:

Name: Cr0security Certified Security Testing
Type: Professional Security Testing Certification  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Dec 11, 2013
Critical Watch

Web Site:

Quote/Declaration: Critical Watch supports MITRE's CVE program for standardizing a naming scheme for vulnerabilities. Incorporating CVE names into our enterprise vulnerability management solution enables our customers to act swiftly and confidently to collapse windows of exposure.

— Nelson Bunker Chief Security Officer
Name: FusionVM Consultant
Type: Appliance-Based Managed Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: FusionVM Enterprise System
Type: Appliance-Based Managed Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: FusionVM MSSP
Type: Appliance-Based Managed Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: FusionVM PCI
Type: Remote Scanning Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: FusionVM Software as a Service (SaaS)
Type: Remote Scanning Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Cronus Cyber Technologies Date Declared: December 1, 2016

Web Site:

Quote/Declaration: Cronus Cyber Technologies, introducing the CyBot Suite is a CVE-vulnerabilities based system that identifies potential attack path scenarios and cyber threats.

Name: CyBot Suite
Type: Attack Path Scenarios Detection  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Dec 1, 2016
CXSecurity Date Declared: January 3, 2012

Web Site:

Name: World Laboratory of Bugtraq (WLB) 2
Type: Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
DragonSoft Security Associates, Inc.

Web Site:

Quote/Declaration: DragonSoft Security Associates, Inc. believes that CVE provides the correct direction to a uniform and consistent representation of vulnerabilities and exposures information. As a company which research and design vulnerabilities and exposures detecting software, we are very desirous to providing CVE compatible product to our customers that researches and designs software for detecting vulnerabilities and exposures, we believe it is important to provide CVE-compatible products to our customers.

Name: DragonSoft Secure Scanner
Type: Vulnerabilities and Exposures Assessment Software  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: DragonSoft Vulnerability Database
Type: Online Vulnerabilities and Exposures Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Easy Solutions, Inc.

Web Site:

Quote/Declaration: As a leader and innovation in the security industry, Easy Solutions, Inc. is pleased to announce compatibility with the CVE Initiative

— Ricardo E. Villadiego, Regional Director, Americas, Easy Solutions, Inc.
Name: Detect Vulnerability Scanning Service - External
Type: Vulnerability Scanning and Assessment Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Detect Vulnerability Scanning Service - External/Internal
Type: Vulnerability Scanning and Assessment Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
EMC Corporation and RSA (The Security Division of EMC)

Web Site:

Quote/Declaration: RSA Archer eGRC Solutions are knowledge management system for the collection, management and distribution of critical security content such as vulnerabilities, technical baselines, control standards and information security policies as they relate to specific risk that IT assets face within the enterprise. The RSA Archer eGRC Solutions suite strongly supports the CVE standard, which greatly assists in our integration with other security products and vendors. The CVE mapping enables our clients to intelligently analyze, cross reference and search vulnerabilities that affect their organization.

Name: RSA Archer GRC
Type: Threat Management  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 25, 2014
Fortinet, Inc. Date Declared: April 5, 2011

Web Site:

Quote/Declaration: Fortinet has been an established security vendor for some time, and regularly discovers third-party security vulnerabilities for which we request CVE Identifiers from MITRE. We also monitor the security space, develop IPS signatures, and map/reference the CVEs for all of these in our advisories and encyclopedia.

Name: FortiGuard
Type: Vulnerability Compliance Management Service and Security Advisories Archive  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
FuJian RongJi Software Company, Ltd

Web Site:

Quote/Declaration: FuJian RongJi Software Company, Ltd., in association with the Institute of High Energy Physics, the Chinese Academy of Sciences, has developed the RJ-iTop Network Vulnerability Scanner System, which provides CVE Output and is CVE Searchable. In addition, its database is fully searchable by keyword or CVE name. We have made our product compatible with CVE so that administrators can easily differentiate which is the best product for them among the different security products.

— C. Shanmao Lin, RongJi Enterprise
Name: RJ-iTop Network Vulnerability Scanner System
Type: Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
GFI Software Ltd.

Web Site:

Quote/Declaration: GFI recognizes the importance of standards in a field which is encountering even bigger challenges, variation of attacks and abuses of IT systems. While searching for a standard which will allow us to adhere to as well as encourage our customers to refer to vulnerabilities in a particular format, we found a perfect synergy between our technology and CVE. We believe that such integration will provide a common ground for our customers and security administrators out there to share and unify experiences against these ever increasing threats.

Name: GFI LANguard Network Security Scanner
Type: Network Vulnerability Assessment & Remediation Product  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Globant

Web Site:

Quote/Declaration: Globant is pleased to support MITRE's initiative of standardizing vulnerability identification in our managed security services. The adoption of MITRE's CVE standard benefits users, community and vendors by providing a consistent and single way of identifying vulnerabilities across different products.

Name: ATTAKA
Type: On Demand Vulnerability Management and Assessment Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
H3C Technologies Co., Limited

Web Site:

Quote/Declaration: H3C Technologies Co., Limited has made our IPS product compatible with CVE for the benefit of our customers and to support industry standards.

Name: SecBlade IPS
Type: Intrusion Prevention System As A Network Switch Module  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecPath T Series IPS
Type: Intrusion Prevention System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Hangzhou DPtech Technologies Co., Ltd. Date Declared: March 23, 2011

Web Site:

Quote/Declaration: Hangzhou DPtech Technologies Co., Ltd. is pleased to support MITRE on the CVE effort to standardize vulnerability identification not only for the security industry, but for our customers. DPtech IPS2000, our network-based intrusion prevention system, and DPtech Scanner1000, our network and application vulnerability assessment scanner, have incorporated CVE names to provide the most valuable information for our customers.

Name: DPtech IPS2000
Type: Network and Application Vulnerability Assessment  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: DPtech Scanner1000
Type: Vulnerability Scanner System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Hewlett-Packard Development Company, L.P.

Web Site:

Quote/Declaration: By integrating CVE into our security assessment and management products we enable our customers to promptly and effectively track and respond to security vulnerabilities.

Name: TippingPoint Next Generation Intrusion Prevention System (NGIPS)
Type: Network-Based Intrusion Prevention System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Jul 29, 2014
High-Tech Bridge SA Date Declared: June 19, 2012

Web Site:

Quote/Declaration: At High-Tech Bridge we strongly believe that CVE information security standard makes security measurable and universal, from which customers, vendors and security researchers benefit. We are grateful to the efforts of MITRE Corporation for continuous CVE standard development and support.

Name: High-Tech Bridge Security Advisories
Type: Security Advisories  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: ImmuniWeb
Type: SaaS Web Application Vulnerability Assessment Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Jun 11, 2013
Hillstone Networks Date Declared: July 26, 2015

Web Site:

Name: Intrusion Prevention System
Type: Hardware Device  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Next Generation Firewall
Type: Firewall  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Apr 4, 2016
HP - Arcsight ESM

Web Site:

Quote/Declaration: As a pioneer and leading provider of security management solutions for the enterprise ArcSight actively promotes and supports open systems standards such as CVE. ArcSight uses cross-device correlation to detect sophisticated multi-source, multi-target attacks while keying into the correct policies and procedures for response via the CVE names. It enables security experts and IT managers to cross-correlate information and references about different threats reported by disparate security products and solutions — a necessity to understand the real impact of vulnerabilities and attacks.

Name: Arcsight ESM Event Security Manager
Type: Real-Time Security Awareness/Incident Response  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 25, 2014
Huawei Technologies Co., Ltd. Date Declared: July 11, 2012

Web Site:

Quote/Declaration: CVE compliance as a high priority requirement throughout Huawei security product/service development process helps our customers to easily get broader vulnerability/exploit information.

Name: Huawei Network Intelligent Protection System (NIP)
Type: Intrusion Prevention System (IPS)  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Huawei Network Intrustion Detection System (NIP D)
Type: Intrusion Detection System (IDS)  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Oct 18, 2016
IBM

Web Site:

Quote/Declaration: IBM actively promotes, supports, and contributes to the emerging open systems standards such as CVE that enable technology management software in the IBM Security portfolio of intrusion detection, vulnerability assessment, end point management, and security management components to inter-operate and share management information. We know that open system standards are a critical step in this direction. We support CVE as the first and the most complete naming convention for vulnerability mapping in the industry and we are committed to using CVE within our product in a tightly integrated fashion.

Name: Rational AppScan
Type: Application Security Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 25, 2014
IBM Internet Security Systems

Web Site:

Quote/Declaration: The CVE naming standard developed by MITRE represents a significant leap forward for the information security industry and end user community. As a technology pioneer and leading provider of security management software and services, IBM Internet Security Systems is pleased to be a part of this important initiative as we move toward a standard that is crucial to the effective protection of every organization's critical digital assets.

— Christopher Klaus, Founder and Chief Technology Officer
Name: Internet Scanner
Type: Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Proventia Enterprise Scanner
Type: Vulnerability Management Assessment System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Proventia Management SiteProtector
Type: Security Management Platform  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: RealSecure Network 10/100
Type: Network-Based IDS/IPS  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: RealSecure Network Gigabit
Type: Network-Based IDS/IPS  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: RealSecure Server Sensor
Type: Host-Based IDS/IPS  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: X-Force Alerts and Advisories
Type: Alerts & Advisories Archive  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: X-Force Database
Type: Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Information Risk Management Plc

Web Site:

Quote/Declaration: IRM ensures that clients acquire and maintain the core elements of information security by providing product-independent, expert, and impartial consulting services to organisations wishing to examine and improve the security of their information assets. It is essential that open and standardised vulnerability descriptions and metrics integrate into IRM's methodology and output so that clients may be assured of a common reference to findings and recommendations. CVE provides such a mechanism and is vital in providing meaningful security threat results.

Name: Security Risk Assessment
Type: Security Risk Assessment Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Information-technology Promotion Agency, Japan (IPA)

Web Site:

Quote/Declaration: IPA is proud to incorporate CVE in our product line. Our main product, JVN iPedia is a vulnerability database that stores summary and countermeasure information on domestic and overseas software products used in Japan. JVN iPedia is equipped with search functions (Keyword, Product, CVSS, CVE, etc.) and RSS feeds, which provides the accumulated data in a comprehensive manner.

Name: Filtered Vulnerability Countermeasure Information Tool (MyJVN)
Type: Filtered Warnings Application  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Vulnerability Countermeasure Information Database (JVN iPedia)
Type: Online Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Mar 3, 2014
Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) and Information-technology Promotion Agency, Japan (IPA)

Web Site:

Quote/Declaration: Under the Information Security Early Warning Partnership in Japan, IPA receives private vulnerability reports and JPCERT/CC coordinates with developers to prepare patches or remedies. JVN provides infomation such as solution, vulnerability analysis by JPCERT/CC, and vender notes. JVN contains CVE information as well as vulnerability attribute information.

Name: Japan Vulnerability Notes (JVN)
Type: Vulnerability Information Portal Site  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Kingnet Security, Inc.

Web Site:

Quote/Declaration: Kingnet Security plays a leading role in network security industry in China. We want our KIDS intrusion detection system to be compatible to the CVE standard so as to bring as much value to our customers as possible.

Name: Kingnet Intrusion Detection System (KIDS)
Type: Intrusion Detection System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
LANDesk Software Inc.

Web Site:

Quote/Declaration: LANDesk Security and Patch manager supports the CVE naming standard, it's a simple and practical way to ensure that a vulnerability definition means the same thing to different people.

Name: LANDesk Patch Manager
Type: Patch Management System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: LANDesk Security Suite
Type: Active Endpoint Security Management  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Oct 4, 2013
Legendsec Technology Co. Ltd

Web Site:

Quote/Declaration: For the benefit of our customers, we believe it is important to be fully compatible with the international CVE standard.

Name: Legendsec SecIDS 3600 Intrusion Detection System
Type: Intrusion Detection System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Legendsec SecIPS 3600 Intrusion Prevention System
Type: Intrusion Prevention System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
LEXSI

Web Site:

Quote/Declaration: The CSI service of laboratory LEXSI gathers applications and services offering a coherent and complete IT security watch solution to its subscribers. At the core of the CSI, ten experts supervise new security failures, carry out integrity tests, provide manual avoidance solutions, reference and enrich the Vulnerabilities Database. Compatibility between referred vulnerabilities and CVE dictionary provides to our subscribers and partners full interworking of our watch system with all third party products and services.

Le service CSI du laboratoire LEXSI regroupe un ensemble d'applications et de services à même d'offrir à ses abonnés une solution cohérente et complète de veille en sécurité informatique. Au coeur du CSI, une dizaine d'experts surveille l'apparition de failles de sécurité, effectue des tests d'intégrité, élabore des solutions de contournement, référence et enrichit la Base de Vulnérabilités. La compatibilité entre les vulnérabilités référencées et le dictionnaire CVE offre à nos abonnés et partenaires l'interopérabilité totale de notre système de veille avec l'ensemble des services et produits tiers.

Name: CSI
Type: Vulnerability Database and Notification Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Lumension Security, Inc.

Web Site:

Quote/Declaration: Lumension Security (formerly PatchLink Corporation) is in the vulnerability management business and as such fully recognizes the value of using CVE names. All of our patches have CVE codes in them.

Name: PatchLink Scan
Type: Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
McAfee, Inc.

Web Site:

Quote/Declaration: Because of today's ever changing threats, and vulnerability data a consent must be had to properly identify each. In the malicious code area these naming conventions exist and are very beneficial. The MITRE CVE program provides a naming standard that can be relied on when there is confusion or no standards agreed upon providing a method by which system administrators and other users can search the Internet to get the information on the same vulnerability via various sources.

— Carl Banzhof - Vice President and Chief Technology Evangelist, McAfee
Name: McAfee Foundstone Appliances
Type: Vulnerability Assessment Appliance  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: McAfee Policy Auditor
Type: Automated Vulnerability Remediation  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Aug 7, 2013
National Institute of Standards and Technology

Web Site:

Quote/Declaration: The National Vulnerability Database contains all CVE information as well as vulnerability attribute information (e.g. vulnerable version numbers), direct access to U.S. government vulnerability resources, and annotated links to industry resources. The underlying data in the database is provided license free via an XML feed.

Name: National Vulnerability Database (NVD)
Type: Online Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
NetClarity

Web Site:

Quote/Declaration: NetClarity is a strong proponent of the CVE dictionary. The Auditor family of appliances automatically audit networks and reports those vulnerabilities discovered by our patent-pending vulnerability assessment engine. With CVE-specific information and remediation instructions, we enable our customers to better manage their risks, comply with regulations, and protect their assets.

— Gary S. Miliefsky, CTO, CISSP, NetClarity, Inc.
Name: NetClarity Analyst and Update Service
Type: Vulnerability Assessment Appliance and Update Service For Small Mobile Networks  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: NetClarity Auditor 128 and Update Service
Type: Vulnerability Assessment Appliance and Update Service For Small Mobile Networks  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: NetClarity Auditor Enterprise and Update Service
Type: Vulnerability Assessment Appliance and Update Service For Large Networks  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: NetClarity Auditor XL and Update Service
Type: Vulnerability Assessment Appliance and Update Service For Small to Medium Enterprises  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Netcraft Ltd.

Web Site:

Quote/Declaration: Netcraft is pleased to be able to offer mappings between its vulnerability scanner and the CVE dictionary. We see CVE as an important security administration tool, linking our services to a wider variety of other security devices, services and sources of security information.

Name: Audited by Netcraft
Type: Managed Vulnerability Scanning Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
NetentSec, Inc. Date Declared: February 5, 2013

Web Site:

Quote/Declaration: NetentSec is a network security company in Beijing of China. We assure that NetentSec Next Generation Firewall is fully compatible with CVE standards.

Name: Next Generation Firewall (NGFW)
Type: Firewall  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Dec 3, 2013
netVigilance, Inc.

Web Site:

Quote/Declaration: The SecureScout line of vulnerability assessment solutions, fully supports CVE references; our speed and ease of use enable users to more efficiently verify CVE coverage.

Name: SecureScout EagleBox
Type: Network Scanning Appliance-Based Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecureScout NX
Type: Single User Network-Based Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecureScout Perimeter
Type: Web-Based, Internet-Side Vulnerability Assessment Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecureScout SP
Type: Enterprise Network-Based Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
NGSSecure, a Division of NCC Group UK PLC Date Declared: February 6, 2012

Web Site:

Quote/Declaration: Since its inception in 2001, NGSSoftware has always made great strides to ensure its software is compatible with the CVE initiative.

Name: NGS SQuirreL for Oracle
Type: Standalone Vulnerability Assessment Software Product  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: November 28, 2012
NileSOFT Ltd.

Web Site:

Quote/Declaration: NileSOFT is proud to incorporate CVE in our product line. Our main products, Secuguard SSE (Host based Vulnerability Assessment Tool), Secuguard NSE (Network based Vulnerability Assessment Tool), mySSE for Web (Online PC Vulnerability Assessment Service), and LogCOPS (Enterprise Log Analysis and Management System) will continue to maintain the latest version of CVE.

Name: Secuguard NSE (Network Security Explorer)
Type: Network based Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Secuguard SSE (System Security Explorer)
Type: Host based Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Secuguard Web Security Explorer (WSE) Webscan
Type: Web Server and Application Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Jun 27, 2016
NSFocus Information Technology (Beijing) Co., Ltd.

Web Site:

Quote/Declaration: CVE has made significant efforts to standardize the names for vulnerabilities, eliminate the potential gap in security coverage and provide easier interoperability among different security products. NSFocus strives to deliver customers the enhanced security by series of products with full support for the CVE standard.

Name: AURORA RSAS
Type: Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: ICEYE NIDS
Type: Intrusion Detection System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: NSFOCUS Network Intrusion Prevention System (NIPS)
Type: Network-Based Intrusion Prevention System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: NSFOCUS Next-Generation Firewall (NF)
Type: Next Generation Firewall  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: NSFOCUS Security Gateway (SG)
Type: Firewall, IDS and Integrated Antivirus  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Mar 11, 2014
Offensive Security Date Declared: November 16, 2010

Web Site:

Name: Exploit Database
Type: Searchable Website  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Packet Storm Date Declared: October 20, 2011

Web Site:

Quote/Declaration: Packet Storm Security, the Internet's largest free security web site housing tools, exploits, advisories, papers, and more, includes CVE names.

Name: Packet Storm Security Web Site
Type: Vulnerability, Tool, and Whitepaper Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Positive Technologies CJSC Date Declared: September 30, 2010

Web Site:

Quote/Declaration: Positive Technologies is a leading provider of vulnerability and compliance management, application security, SCADA security and penetration testing. As one of the development directions, we decided to use the SCAP technology in our products. We are implementing OVAL standards, supporting FDCC/USGCB, and maximizing integration with other open security standards in our products. We also provide an open OVAL repository containing vulnerability descriptions collected from various sources.

Name: MaxPatrol
Type: Vulnerabilities and Compliance Management System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Apr 22, 2014
Qualys

Web Site:

Quote/Declaration: Qualys is pleased to support MITRE's CVE Initiative of standardizing vulnerability identification and has incorporated the CVE naming scheme into its QualysGuard Web Services Architecture.

— Wolfgang Kandek, CTO & Vice President of Engineering
Name: QualysGuard Consultant
Type: Network and Application Vulnerability Assessment Platform  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: QualysGuard Express
Type: Network and Application Vulnerability Assessment Platform  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: QualysGuard MSP
Type: Network and Application Vulnerability Assessment Platform  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: QualysGuard Vulnerability Management
Type: Network and Application Vulnerability Assessment Platform  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Rapid7 LLC

Web Site:

Quote/Declaration: As a leader in both vulnerability management and penetration testing, Rapid7 appreciates MITRE's efforts to provide unique CVE Identifiers across both of these areas. This enables our customers to easily reference vulnerabilities and exploits across systems.

Name: Metasploit Express
Type: Vulnerability Management and Penetration Testing  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Metasploit Pro
Type: Vulnerability Management and Penetration Testing  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: NeXpose
Type: Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Red Hat, Inc.

Web Site:

Quote/Declaration: It is often confusing when the same security issues get fixed by different vendors in different ways with different names and descriptions. We see the CVE Initiative as the way to solve this problem, giving the community accurate information on which they can base their security decisions. We are working with MITRE to contribute and validate new entries as well as publish CVE entries in our security advisories.

— Mark Cox, Senior Director of Engineering
Name: Red Hat Security Advisories
Type: Advisory Capability  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: October 24, 2012
Rsam Date Declared: February 7, 2011

Web Site:

Quote/Declaration: Rsam's Enterprise GRC platform has integrated CVE throughout all vulnerability management and assessment modules. Since 2005, customers have utilized Rsam and CVE to declare, search, and reporting on common vulnerabilities, and to harmonize common vulnerability data across disparate data sources.

Name: Rsam
Type: Enterprise Governance, Risk and Compliance (EGRC) Platform  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
SAINT Corporation

Web Site:

Quote/Declaration: SAINTbox and SAINT Security Suite vulnerability analysis, reports and tutorials include relevant CVE links, providing the user with easy reference to related information and a basis for determining the extent of the product's capabilities. SAINTbox and SAINT Security Suite are also CVE Searchable with a CVE cross-reference that maps the CVE entries to the SAINT tutorials. SAINTCloud is a hosted security tool suite that includes vulnerability analysis, penetration testing, configuration auditing and reporting. Analytics, Reports and Tutorials include relevant CVE links, providing the user with easy reference to related information. SAINT Cloud is also CVE Searchable with a CVE cross-reference in the Scan Policy grid that maps the CVE entries to tutorials.

Name: SAINT Security Suite
Type: Network Vulnerability Scanning Appliance  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SAINTCloud
Type: Network Vulnerability Scanning and Remediation  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SAINTbox
Type: Network Vulnerability Scanning Appliance  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Nov 3, 2016
Sangfor Technologies Co., Ltd. Date Declared: February 6, 2012

Web Site:

Quote/Declaration: Sangfor Technologies Co., Ltd. is a leading network security company in China. We fully support MITRE's CVE standard in our security products, which allows our security research and product development teams to focus on adding value for our customers and enables our customers to easily reference vulnerabilities information.

Name: Next Generation Application Firewall (NGAF)
Type: Next Generation Application Firewall  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
SecPoint ApS

Web Site:

Quote/Declaration: SecPoint's vulnerability assessment, vulnerability scanning solution integrates CVE to allow users the best searchable way for vulnerabilities.

Name: SecPoint Cloud Penetrator
Type: Web Vulnerability Scanner  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecPoint Penetrator
Type: Vulnerability Scanner  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecPoint Portable Penetrator
Type: Wi-Fi Security Audit Suite  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecPoint Protector UTM Firewall
Type: UTM Firewall with Vulnerability Scanning and Vulnerability Assessment  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Aug 13, 2013
SECUI.COM Corporation Date Declared: June 22, 2011

Web Site:

Quote/Declaration: With the increasing number of vulnerabilities in various areas, it is worthwhile to define a common vulnerability naming and enumerating standard such as CVE List. By providing this information to our customers through our product, they can quickly and accurately identify vulnerabilities. Especially, customers can cross-link the information with other CVE-Compatible products and services.

Name: SECUI SCAN
Type: Vulnerability Assessment Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Secunia

Web Site:

Quote/Declaration: Secunia constantly monitors and reviews CVE entries to ensure that these are appropriately and accurately matched with the verified Secunia Vulnerability Intelligence provided in our Advisories, Secunia PSI, Secunia CSI, Secunia OSI, Secunia VIM, and on our Web site.

Name: Secunia VIM (Vulnerability Intelligence Manager)
Type: Vulnerability Intelligence, Alerting, Management, and Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Secunia Website
Type: Vulnerability Database and Security Advisory Archive  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Sep 30, 2013
SecureInfo Corporation

Web Site:

Quote/Declaration: SecureInfo RMS, award-winning certification and accreditation software, is CVE-compatible. Supporting CVE is an important part of our vision in providing continuous monitoring capabilities in support of FISMA and our customer's information security programs.

— Roberto R. Garcia, V.P. Product Engineering
Name: Risk Management System (RMS)
Type: Compliance Framework Tool  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Security-Database

Web Site:

Quote/Declaration: Security Database uses the publicly known vulnerabilities identified in the CVE List as the basis for most of the queries. All data are relayed in realtime.

Name: Security Database Website
Type: Web site services  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Mar 3, 2014
Serkan Ozkan Date Declared: November 3, 2010

Web Site:

  Last Updated: Jan 6, 2016
Shenyang Neusoft System Integration Co., Ltd Date Declared: January 25, 2011

Web Site:

Name: NISG-IPS
Type: Intrusion Prevention Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Jul 14, 2014
Silicomp-AQL

Web Site:

Quote/Declaration: CVE compatibility ensures that administrators can easily use different security products in order to find additional information they need.

Name: Vigil@nce
Type: Online Vulnerability Database (French)  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Skybox Security Inc.

Web Site:

Quote/Declaration: Skybox Security maintains CVE Compatibility because CVE is the standard reference in the industry for vulnerability information and allows correlation of information coming from different security solutions.

Name: Skybox View Enterprise Suite
Type: Network Security Management Software  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Sep 5, 2013
Software in the Public Interest, Inc.

Web Site:

Quote/Declaration: Debian developers understand the need to provide accurate and up-to-date information of the security status of the Debian distribution, allowing users to manage the risk associated with new security vulnerabilities. CVE enables us to provide standardized references that allow users to develop a CVE-enabled security management process.

Name: Debian Security Advisories
Type: Advisories  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Symantec Corporation

Web Site:

Quote/Declaration: Symantec maintains one of the largest vulnerability databases available today. Consisting of over 9000 distinct vulnerability records, we have strived to maintain CVE compliance from the outset of the CVE Initiative.

Symantec fully supports an industry-wide standard for the indexing of vulnerabilities. Our public web sites (SecurityFocus and SecurityResponse), and our commercial alerting services (DeepSight Alert Services) fully conform to the CVE requirements. This allows our customers to search for, and research vulnerabilities and blended threats using this common nomenclature. Symantec's wide range of security products utilize the industry-leading vulnerability database and employ trusted, fast and automated response capabilities to identify threats identified by CVE.

Name: DeepSight Alert Services
Type: Vulnerability Alerting Service and Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecurityFocus Vulnerability Database
Type: Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Tenable Network Security Inc.

Web Site:

Quote/Declaration: Tenable Network Security utilizes the CVE program to reference each of the vulnerabilities detected by Nessus and the Passive Vulnerability Scanner. This information is also heavily used through SecurityCenter for reporting, education, IDS event correlation and linking with third-party security information.

Name: Nessus Security Scanner
Type: Vulnerability and Compliance Scanner  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Passive Vulnerability Scanner
Type: Passive Network Monitor  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: Security Center
Type: Enterprise Security Management System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
ThreatGuard, Inc.

Web Site:

Quote/Declaration: Recognizing the importance of common indexing of known vulnerabilities, ThreatGuard has included CVE references in ThreatGuard VMS and ThreatGuard Traveler. These references are seamlessly integrated with the ThreatGuard Navigator client application, reports, and search engine. As we release new vulnerability tests, it is among ThreatGuard's top priorities to ensure CVE referencing is included and accurate, extending the efforts of the CVE initiative.

Name: ThreatGuard Traveler
Type: Continuous Security Auditing and Compliance Management for Service Providers  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: ThreatGuard Vulnerability Management System
Type: Continuous Security Auditing and Compliance Management  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
TMC y Cia

Web Site:

Quote/Declaration: We have aligned our service/appliance FAV with the CVE vulnerabilities standard for the benefit of our customers.

Name: FAV - Falcon Vulnerabilities Analysis
Type: Vulnerability Analysis Service/Appliance  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
ToolsWatch Date Declared: Jul 22 2015

Web Site:

Quote/Declaration: ToolsWatch provides vFeed a fully aggregated, cross-linked and standardized Vulnerability Database based on CVE and industry standards such as CWE, OVAL, CAPEC, CPE, CVSS etc. So we strongly believe the importance of the standardization efforts driven by MITRE. Therefore, vFeed will definitely continue to support the CWE initiative and is pleased to ensure the CWE Compatibility for its vFeed Vulnerability Database Community and all derived products and services.

Name: vFeed API and Vulnerability Database Community
Type: Open Source Correlated and Cross-Linked Vulnerability XML Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Apr 26, 2016
Trend Micro, Inc.

Web Site:

Name: Trend Micro Vulnerability Assessment
Type: Vulnerability Assessment Product with Virus Info Association  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Tripwire, Inc.

Web Site:

Quote/Declaration: Tripwire actively supports standardization efforts in the security market, including the CVE's common lexicon for the vulnerability namespace. As a member of the CVE editorial board, we are committed to ensuring Tripwire's IP360 product continues to support CVE names and provides customers with an enterprise-class complete lifecycle approach to vulnerability management. Ultimately, this enables customer to find and eliminate vulnerabilities before they can be exploited, ensure security policy compliance and meaningfully measure and manage business risk.

— Tim Keanini
Name: Tripwire IP360
Type: Appliance-Based Enterprise-Class Vulnerability Management System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Jun 18, 2014
TrustSign Date Declared: December 28, 2011

Web Site:

Quote/Declaration: TrustSign is a certificate authority and a security company that works to identify and correct common vulnerabilities in enterprise networks and service providers. We believe that it is important to our services and clients to be a fully compatible with the CVE standard.

Name: Selos de Seguranca
Type: Vulnerability Assessment and Remediation Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Trustwave

Web Site:

Quote/Declaration: We are pleased to partner with MITRE on the CVE Compatibility program. As a leader in the enterprise security management software technology, we believe that the CVE standardization of multi-vendor security exploits information will greatly benefit our customers. Our current product offering leverages CVE to offer intelligent correlation and threat and incident management solutions and our future offerings will continue to leverage the widely accepted CVE standard.

— Paul MacGyver Carman, Technical Product Manager
Name: TrustKeeper
Type: Vulnerability Scanning Service  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 25, 2014
Virtustream, Inc. Date Declared: July 25, 2014

Web Site:

Quote/Declaration: Virtustream has solidified our use of a standards based solution by working with the MITRE CVE Team to certify our Analytic Continuous Monitoring Engine (ACE) product as CVE-Compatible.

Name: Analytic Continuous Monitoring Engine (ACE)
Type: Enterprise Risk Management and Continuous Monitoring  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Jul 28, 2014
WINS Co., Ltd.

Web Site:

Quote/Declaration: WINS Co., Ltd. is pleased to support MITRE on the CVE effort to standardize vulnerability identification not only for the security industry, but for our customers. SNIPER IPS, our network-based intrusion prevention system, and SecureCast, our vulnerability database, have incorporated CVE names to provide the most valuable information for our customers.

Name: SNIPER IPS
Type: Network-Based Intrusion Prevention System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: SecureCAST
Type: Vulnerability Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Apr 4, 2014
WPScan Date Declared: Nov 13, 2014

Web Site:

Quote/Declaration: The WPScan Vulnerability Database aims to record WordPress core, Plugin, and Theme vulnerabilities. We use CVE numbers to allow users to reference vulnerabilities across different sources as well as giving the user extra valuable information about the vulnerability itself.

Name: WPScan Vulnerability Database
Type: Database  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
  Last Updated: Feb 3, 2015
Xi'an Jiaotong University Jump Network Technology Co., Ltd.

Web Site:

Quote/Declaration: We have incorporated CVE to improve the quality of our product.

Name: Jump NVAS
Type: Network Vulnerability Assessment System (NVAS)  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
Name: JumpIPS
Type: Intrusion Prevention System  
CVE Output: Yes
CVE Searchable: Yes
Review Completed Questionnaire
 
Page Last Updated or Reviewed: September 27, 2017