About Security Alerts
What is in scope, where it comes from, and what DeSpy does not claim.
What is in scope
- Every entry in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- Every advisory in CISA's CSAF feeds (OT, IT and VA).
- CVE records whose CVE Numbering Authority (CNA) names, as the affected vendor, a maker DeSpy follows — the list below.
What is not covered
- CVEs about makers DeSpy does not follow, unless CISA lists them in KEV or an advisory.
- Records whose CNA names no vendor, or a vendor spelling DeSpy does not match to a maker it follows. A maker named only by an Authorized Data Publisher (such as CISA-ADP), not by the CNA, does not bring a CVE into scope.
- CVE records NVD has not changed since DeSpy began collecting them, unless CISA lists them in KEV: DeSpy collects CVE records as NVD adds or changes them, so an older record that has not changed since is not here.
- Vendor security bulletins, CERT/CC notes, GitHub and OSV advisories, and EPSS scores.
- Whether your own device, hardware revision or firmware is affected. No record here says that, and a missing record does not say the opposite.
How records are shown
Every record is the source's own statement: its description, status, tags and labels are printed as the source published them, and each page names who wrote what. Each record page also says where DeSpy collected it: “Collected from the National Vulnerability Database (NVD)” for a CVE, “Collected from CISA's CSAF advisory feed” for a CISA advisory. DeSpy adds no severity, verdict or summary of its own, and security records never change a device's privacy grade.
When a record's CNA is not the maker it names, the page says so: “Filed by <CNA>; not a statement by <maker>.” Products an Authorized Data Publisher added to a CVE record are shown under that publisher's name, never as the CNA's. An NVD status of Deferred, Received or Awaiting Analysis means NVD has not analysed that CVE. A CVE the source has rejected keeps its page, marked as withdrawn.
A record links to a device in DeSpy's IoT catalog only when the source's vendor and model are exactly the device's recorded vendor and model. A word naming the kind of device (“DIR-605 Router”) is not part of the model; a revision or a product line is. A match on the maker alone makes no link.
Makers in scope
The makers DeSpy follows: every maker of a device in DeSpy's IoT catalog, and every maker it already followed when that maker's devices left the catalog, named as the catalog recorded them:
- 23andMe, Inc.
- Abbott Laboratories
- ACTi / ACTI Communications
- Acusensus
- Adaptive Recognition
- ADT Inc.
- Aegis
- AFR Engine
- alhua
- Allstate / Arity
- Altumint
- Amazon / Amazon.com, Inc. — also matched as: amazon.com
- Amcrest
- American Traffic Solutions
- AngelSense, Inc.
- Anker Innovations (Eufy) — also matched as: eufy
- AnyVision
- Apple Inc.
- Aqara (Lumi United Technology)
- Argus
- Arlo Technologies
- ARVOO DIAMOND
- ASUS
- August Home (ASSA ABLOY)
- Auto Patrol
- Automotus
- AutoVu
- AutoVu Cloudrunner
- Auvisa
- Avast
- AVIGILON / Avigilon
- Axis Communications
- Axis Q1800
- Axon
- Axon Enterprise / Outpost
- Bark Technologies, Inc.
- BioWink GmbH
- Blink (Amazon)
- Blue Line Solutions
- BMW Group
- Bosch Security Systems
- BSH Home Appliances (Bosch)
- Chamberlain Group
- ChargePoint Holdings
- Clearview AI
- Comcast (Xfinity)
- Coreforce
- CoStar
- crime fighters
- Cross Camera Controls
- Cyber Secure
- CyclopsTechnologies
- D-Link — also matched as: dlink
- Dahua / Dahua Technology
- DataWorks Plus
- De'Longhi
- Dexcom, Inc.
- DJI
- Dr. Ing. h.c. F. Porsche AG
- DrayTek
- Dura Tech
- Dyson
- Eagle Eye
- ecobee
- Ecovacs Robotics
- Edimax
- eero LLC
- Eight Sleep
- Ekin
- Electronic Technology Inc
- ELSAG
- Emporia Energy
- EPIC iO / EPIC IO Technologies
- Extreme CCTV
- Eyehawk technologies
- FACESNXT
- Federal Signal
- Flir
- Flock Safety
- Ford Motor Company
- Fusus
- Garmin Ltd.
- GE Appliances
- General Motors / OnStar
- Genetec
- Google LLC — also matched as: android (associated with google inc. or open handset alliance), google devices
- Govee
- Gridless
- Gridless Sentry
- Hanwha Vision
- Happiest Baby, Inc.
- Heymans
- HIK Vision(Chinese Manufacturer)
- Hikvision — also matched as: hangzhou hikvision digital
- hikvison
- Hinovision Solutions LLC (Linovision USA)
- Hisense
- Honda Motor Co.
- HP Inc.
- Humane Inc.
- Hyundai Motor Company
- ICamera
- Idemia
- INEX Tech
- Innovative Solutions
- Insight
- Insight LPR
- Intelisite
- iRobot
- Iteris
- Itron
- Jaguar Land Rover
- Jenoptik
- John Hancock (Manulife)
- June Life (June Oven)
- Kapsch TrafficCom
- Kapsch VRX-350x
- Kedacom
- Keurig Dr Pepper
- Kia Corporation
- L3 Mobile-Vision
- Landis+Gyr
- Lector Vision
- LetsDriveSafer.com
- LexisNexis
- LG Electronics
- Life360, Inc.
- LineView Technologies
- Linovision
- live view technology
- LiveView Technologies (LVT)
- Logix ITS Enforcer Plus
- Lorex Corporation
- Lovense (Shenzhen Lianwan Technology)
- LT Security Incorporated
- Lumen
- LVR
- LVT Mobile Tower
- Macq
- Major Police and Fire Supply
- Martel Electronics
- Masterbuilt
- Mav (IQ:350XR)
- Mazda Motor Corporation
- Meari Technology
- Mercedes-Benz Group
- Mesa Technologies
- Meta Platforms, Inc.
- MikroTik
- Milestone
- Miovision
- Mobile Pro Systems
- Mobotix
- Moen (Fortune Brands Innovations)
- Montavue
- Motorola/Aviglon
- Motorola Solutions
- Motorola/Vigilant
- MPH Industries
- MyFitnessPal, Inc.
- Nanit, Inc.
- NDI Recognition Systems
- NEC
- Neg Micon
- Neology
- NETGEAR
- Nissan Motor Co.
- Novoa Global
- NovoaGlobal
- NuPark
- NUUO
- Obsidian Integration
- oculens
- Oosto
- OpenALPR
- OpenALPR/Rekor
- Oura Health
- Owlet Baby Care
- PaceTalk
- Packetalk
- Park Assist
- Pelco
- Peloton Interactive
- perkons
- Petcube
- Philips (Sonicare)
- PIPS / PIPS Technology
- PlateLogiq
- PlateScan
- PlateSmart
- PlateSmart/CyclopsTchnlgs
- Platesmart PTZ LPR
- Plume Design, Inc.
- Procter & Gamble (Oral-B)
- Proctorio
- PTZOptics
- QNAP
- Rachio, Inc.
- Raytheon
- Reconyx
- red speed
- Redflex
- RedSpeed
- Redspeed Redcurb
- Rekor Systems
- Reolink Innovation Inc.
- Resideo Technologies, Inc.
- RetailNext
- Ring Inc / Ring LLC
- Rivian Automotive
- Roborock (Beijing Roborock Technology)
- Roku, Inc.
- RTX Corporation
- SafePassage
- Samsung Electronics — also matched as: samsung mobile, samsung tv & appliance
- Scientel Solutions
- Secure Technical Systems
- Secure Technical Solutions
- Securewatch 24
- Selex
- Sense Labs
- Sensys Gatso Group
- Siemens
- Signify (Philips Hue)
- simec
- SimpliSafe, Inc.
- SiteSecure
- Skycop
- Sleep Number Corporation
- Smarter
- Sonos, Inc.
- Sony Group Corporation
- soundvue noise camera
- spot ai
- Standard Innovation Corporation (We-Vibe)
- Stare
- Stellantis
- Strava, Inc.
- Subaru Corporation
- Sumavision
- SwitchBot
- Targa System
- Tattile
- TCL Technology
- Tempdrop
- Tenda
- Tesla, Inc.
- Teva
- Thomson Reuters CLEAR
- Tile, Inc.
- Tomofun
- Toyota Motor Corporation
- TP-Link — also matched as: tplink, tp link, tp-link system
- Tractive GmbH
- Traeger
- TransCore
- Turing
- Turing AI
- Turing SkyShield
- Turn-Key Mobile Inc
- Ubicquia / Ubicquia Inc
- Ubiquiti
- Ubiquiti Networks
- UniFi
- Uniview / Uniview Technologies
- Unv
- UTILITRA
- VanMoof B.V.
- Veritone
- Verkada / Verkada Inc
- Verra Mobility
- Vetted Security Solutions
- Vicon Security
- Video Plate Hunter
- Viewtron
- Vigilant Solutions
- Vivotek
- VIZIO Inc.
- Volkswagen Group
- Volvo Cars
- VTech Holdings Ltd.
- Vue Robotics
- WCCTV
- Weber Inc.
- Whirlpool Corporation
- Whisker
- Whistle Labs
- WHOOP, Inc.
- Withings
- Wyze Labs
- Xiaomi
- Yuneec
- Zaladium
- Zhejiang Uniview Technologies Co., Ltd
- Zyxel
Vendor spellings DeSpy treats as one maker
DeSpy ignores case and spacing, a trailing part in brackets, everything after “ / ” (so “Allstate / Arity” is read as Allstate), and trailing legal or corporate words (Inc., Incorporated, LLC, Ltd., Limited, Co., Ltd., Co., Corp., Corporation, Company, GmbH, AG, S.A., B.V., PLC, Pte, Pty, Oy, AB, KK, Holding or Holdings, Group, Electronics, Technology or Technologies, System or Systems, Innovation or Innovations, Lab or Labs, Communications), so “Samsung Electronics” and “Samsung” are one maker. It also reads these spellings as the maker shown:
- “amazon.com” is read as amazon
- “eufy” is read as anker
- “dlink” is read as d-link
- “android (associated with google inc. or open handset alliance)” is read as google
- “google devices” is read as google
- “hangzhou hikvision digital” is read as hikvision
- “samsung mobile” is read as samsung
- “samsung tv & appliance” is read as samsung
- “tp link” is read as tp-link
- “tp-link system” is read as tp-link
- “tplink” is read as tp-link
Sources and licences
- NIST NVD CVE API 2.0 — This product uses the NVD API but is not endorsed or certified by the NVD.
- The CVE Program — CVE records and CNA descriptions. Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
- CISA Known Exploited Vulnerabilities catalog — CC0 1.0.
- CISA CSAF advisories — shown with the TLP label each document carries, subject to CISA's Notification.
CVE Program Terms of Use
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN PROVIDED BY MITRE ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.
Corrections
These records are their sources' own. To correct a record, contact the CNA that filed it or CISA. If DeSpy copied a record wrongly or linked it to the wrong device, email privacy@despy.app.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.