← Security Alerts

About Security Alerts

What is in scope, where it comes from, and what DeSpy does not claim.

What is in scope

What is not covered

How records are shown

Every record is the source's own statement: its description, status, tags and labels are printed as the source published them, and each page names who wrote what. Each record page also says where DeSpy collected it: “Collected from the National Vulnerability Database (NVD)” for a CVE, “Collected from CISA's CSAF advisory feed” for a CISA advisory. DeSpy adds no severity, verdict or summary of its own, and security records never change a device's privacy grade.

When a record's CNA is not the maker it names, the page says so: “Filed by <CNA>; not a statement by <maker>.” Products an Authorized Data Publisher added to a CVE record are shown under that publisher's name, never as the CNA's. An NVD status of Deferred, Received or Awaiting Analysis means NVD has not analysed that CVE. A CVE the source has rejected keeps its page, marked as withdrawn.

A record links to a device in DeSpy's IoT catalog only when the source's vendor and model are exactly the device's recorded vendor and model. A word naming the kind of device (“DIR-605 Router”) is not part of the model; a revision or a product line is. A match on the maker alone makes no link.

Makers in scope

The makers DeSpy follows: every maker of a device in DeSpy's IoT catalog, and every maker it already followed when that maker's devices left the catalog, named as the catalog recorded them:

Vendor spellings DeSpy treats as one maker

DeSpy ignores case and spacing, a trailing part in brackets, everything after “ / ” (so “Allstate / Arity” is read as Allstate), and trailing legal or corporate words (Inc., Incorporated, LLC, Ltd., Limited, Co., Ltd., Co., Corp., Corporation, Company, GmbH, AG, S.A., B.V., PLC, Pte, Pty, Oy, AB, KK, Holding or Holdings, Group, Electronics, Technology or Technologies, System or Systems, Innovation or Innovations, Lab or Labs, Communications), so “Samsung Electronics” and “Samsung” are one maker. It also reads these spellings as the maker shown:

Sources and licences

CVE Program Terms of Use

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN PROVIDED BY MITRE ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.

Corrections

These records are their sources' own. To correct a record, contact the CNA that filed it or CISA. If DeSpy copied a record wrongly or linked it to the wrong device, email privacy@despy.app.

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.

Scope, sources and licences →