Evidence-backed facts
- U.S. National Institute of Standards and Technology documents Common Platform Enumeration product records, match strings, identifiers, references, pagination, and documented API behavior. informative
- Public reads and API-key use do not grant product, vendor, vulnerability, federal, standards, or NIST authority. informative
- Clients must bind CPE name or match criteria, product or vendor fields, date range, pagination, API key, rate guidance, and response version. informative
- CPE matching and product metadata can be incomplete, generalized, delayed, or changed and do not prove software identity, presence, vulnerability, exploitability, support, or safety. informative