cve.icu - CVE Intelligence for Splunk app icon

cve.icu - CVE Intelligence for Splunk

Ingest the complete CVE V5 database (327,000+ vulnerabilities) into Splunk in minutes. Features bulk ZIP downloads, hourly delta updates, CVSS/EPSS/KEV/SSVC risk enrichment, and four Dashboard Studio dashboards. Works out of the box with no API keys or setup required.

Built by
splunk product badge
screenshot
screenshot
screenshot
screenshot

Latest Version 2.0.3
April 18, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.3, 10.2, 10.1, 10.0
Rating

5

(2)

Log in to rate this app
Support
cve.icu - CVE Intelligence for Splunk support icon
Developer Supported app
The cve.icu add-on ingests the complete CVE V5 database directly into Splunk. Unlike traditional collectors that rely on slow per-CVE API crawling, this add-on streams data from official GitHub release ZIP files, enabling initial ingestion of over 327,000 CVE records in minutes. Hourly delta updates keep the data current with only a few API calls per run -- no GitHub token required. Key Features: Full CVE V5 Schema Support: Parses the modern CVE JSON 5.x schema including cveMetadata, CNA containers, and CISA-ADP enrichment. Extracts CVSS scores across all versions (v2.0, v3.0, v3.1, v4.0), CWE classifications, and affected product/vendor data. Risk Prioritization Beyond CVSS: Integrates three enrichment sources to help security teams identify "patch now" threats: FIRST Exploit Prediction Scoring System (EPSS) scores updated daily, CISA Known Exploited Vulnerabilities (KEV) catalog refreshed every 6 hours, and CISA SSVC (Stakeholder-Specific Vulnerability Categorization) decision data from ADP containers. Four Dashboard Studio Dashboards: CVE Explorer for searching and filtering the full database, Risk Priority for EPSS/KEV/SSVC-ranked threat triage, Vulnerability Landscape for executive-level trend analysis, and Operational Health for monitoring ingestion status and errors. Production-Ready Architecture: Resource-aware modular input with memory monitoring (512MB limit), cooperative timeout management, and KV Store checkpointing with file fallback. Pre-computed lookup CSVs power dashboard KPIs so panels load instantly without running expensive searches. Splunk Cloud compatible and AppInspect validated. Zero-Configuration Start: Works out of the box -- install and data starts flowing. No API keys, no setup pages, no index creation required. Customize the target index via the cveicu_index macro when ready.

Categories

Security, Fraud & Compliance, Threat Intel

Created By

Jerry Gamblin

Type

app

Downloads

85

Resources

Log in to report this app listing