A vulnerability database that preserves every change.
Farion aggregates vulnerability data from public databases, vendor advisories, distribution trackers, and exploit sources, normalizes the records, and retains the complete history behind every update.
Search across sources without losing their differences.
Filter vulnerabilities by full-text search, package ecosystem, CVSS, KEV, EPSS, affected package, fix availability, source, and other available attributes. Open a vulnerability to review every contributing source and the normalized Farion record.
Overview
Sources
Packages
History
Affected versions
Fixed versions
CVSS
KEV
EPSS
Exploit intelligence
References
See what changed, when it changed, and which source changed it.
Farion versions every advisory update. The History view shows when descriptions, references, severity, CVSS, EPSS, exploit maturity, affected packages, affected versions, and fix information were added or modified.
Update vulnerability decisions several times per day.
Farion continuously collects and normalizes available vulnerability information. When an advisory changes, existing SCA findings can be reassessed with the new affected versions, exploit signals, severity, references, or fix information.
Do not depend on a single vulnerability database.
Sources include NVD, OSV, GitHub Security Advisories, CISA KEV, FIRST EPSS, GitLab Advisory Database, RustSec, the Python Packaging Advisory Database, Linux-distribution security trackers, direct vendor advisories, and public exploit or proof-of-concept information.
Connect global vulnerability intelligence to local application evidence.
A global advisory explains the vulnerability. Farion combines that intelligence with dependency usage, vulnerable-function reachability, tainted paths, routes, code context, and configured deployments to assess the finding in the application where it was discovered.
Frequently asked questions
Yes. Every advisory version is retained, including changes to descriptions, references, severity, EPSS, exploit maturity, affected packages, affected versions, and fixes.
Yes. Existing findings can be reassessed when sources publish new affected versions, fixes, exploit information, scores, or references.
Related capabilities
See how Farion works on your application.
Request a guided evaluation or walk through the relevant workflow with our technical team.