Vulnerability-Lookup 5.3.0 released (www.vulnerability-lookup.org)
from cedric@lemmy.ml to security@lemmy.ml on 07 Jul 10:16
https://lemmy.ml/post/49722284

We are pleased to announce the release of Vulnerability-Lookup 5.3.0!

This release brings email subscriptions to KEV catalogs, letting you receive batched digests whenever new exploited vulnerabilities are added to a catalog you follow. Search gained the long-requested ability to filter and sort by CVSS base score, two new feeder families join the platform — the AVID (AI Vulnerability Database) feeder and a set of new CSAF vendor feeders — and the KEV catalogs page gained a whole suite of coverage visualisations. On the account side, 2FA recovery codes make account recovery safer.

What’s New

Email subscriptions to KEV catalogs

You can now subscribe to any KEV catalog and receive batched email digests when new entries are added. Subscriber counts are surfaced on the catalogs page, and the notifications page was modernized onto the shared card design language (#457).

Filter and sort by CVSS base score

The search now supports filtering and sorting vulnerabilities by CVSS base score — including CVSS-only searches that need no vendor, product or assigner. The recent vulnerabilities page gained a quick-filter accordion above the table, and the search form now preselects the CVE Program source by default (#454).

New feeders: AVID and more CSAF vendors

A new feeder for the AVID (AI Vulnerability Database) brings AI-specific vulnerability advisories into the platform, with a dedicated advisory view, product search wiring and source registration. Contributed by @thunderstornX in #442.

We also added new CSAF feeders for the vendors whose public feeds actually deliver documents — audited from a much larger candidate list — wired into the web interface and README. Along the way: CERT@VDE trusted-provider metadata URLs were fixed for 12 vendors, the TuxCare feeder now points at its published provider metadata, Palo Alto advisory ids were namespaced so they no longer overwrite canonical CVE records, and the csaf_trend feeder was renamed to csaf_trendmicro (#448).

KEV catalog coverage visualisations

Building on the catalog coverage matrix introduced in 5.2.0, the KEV catalogs page gained a set of coverage visualisations:

2FA recovery codes

Accounts protected with two-factor authentication can now generate recovery codes for account recovery, and the profile page was restructured into themed cards (#435).

Favorite feed

Users can pick a favorite feed used as the default source on the recent vulnerabilities page, and toggle it directly from that page.

Readable RSS/Atom feeds

RSS/Atom feeds now render as readable pages when opened in a browser: server-side rendering via content negotiation, KEV Atom content emitted as XHTML, and the XSL stylesheet made XSLT 1.0 compatible and served as application/xslt+xml so Chromium-based browsers apply it.

API improvements

Other new features

Changes

Fixes

Changelog

📂 For the full list of changes, check the GitHub release:
github.com/vulnerability-lookup/…/v5.3.0

🙏 A big thank you to all contributors and testers!

Feedback and Support

If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:
github.com/vulnerability-lookup/…/issues/
Your feedback is always appreciated!

Follow Us on Fediverse/Mastodon

You can follow us on Mastodon and get real-time information about security advisories:
social.circl.lu/@vulnerability_lookup/

#security

threaded - newest