Disclaimer
Best-effort public-service · No warranty of any kind
1. Research & defence reference only
Content is provided solely for security research and defensive purposes. It does not constitute security advice, legal advice, or any other form of professional opinion.
2. No SLA / no liability for delay
vulnti.work is a best-effort public-service. It carries no SLA commitment of any kind and accepts no liability for delays, omissions, errors, or service interruptions.
3. Subscribers must self-verify
Subscribers must validate all intelligence against their own environment, technology stack, and threat model. All scoring, impact analysis, and triage published here is reference material; the decision authority rests with the subscriber.
4. No liability for reliance
The platform accepts no liability for any direct or indirect loss resulting from reliance on its content, including but not limited to business disruption, data loss, compliance penalties, or reputational harm.
5. Copyright & fair use
All content is referenced from public sources; copyright remains with the original publishers. CH-4 social-channel content (WeChat / Twitter) is used under fair-use: summary ≤300 chars + verbatim key-passage quote ≤200 chars + outbound link to original + mandatory attribution. Full-text mirroring is prohibited.
6. Not a PoC weaponization platform
Content does not constitute PoC weaponization and does not encourage offensive behaviour. ExploitDB-class entries link only to metadata (CVE / affected versions / exploit type) and the original PoC; working exploit payloads are not mirrored. Report misuse to the operator via the GitHub Issues channels listed in /legal §7.
7. AI-assisted content must be verified against the source
Chinese-localised summaries, impact analysis, and detection / mitigation guidance on this site are produced by an AI pipeline. Every AI-triage step records an auditable, stored trace_id, and outputs are constrained to the input materials via substring and structural validation — but translation drift and contextual loss cannot be entirely ruled out. Before acting on any entry, subscribers should treat the original source (NVD / GHSA / CNNVD / vendor PSIRT / mailing-list archive) as authoritative; AI-generated text on this site is not a substitute for the original advisory.
8. Retraction & takedown channel
If an original author, copyright holder, regulator, or reader raises a copyright objection, factual correction, or compliance concern about any entry, submit it through the channels listed in /legal §7. Confirmed errors are published on the /retractions page. The maximum response window is 48 hours (aligned with the 48-hour notification mechanism under Article 9 of the PRC Network Product Security Vulnerability Management Regulations); the actual handling time depends on the sufficiency of supporting evidence.