Software vulnerabilities continue to pose significant threats to modern information systems, requiring a timely and accurate risk assessment. Public repositories, such as the National Vulnerability Database and CVE details, are regularly updated, but predominantly utilize relational data models that lack native support for representing complex, interconnected structures. To address this, recent research has proposed graph-based vulnerability models. However, these systems often require complex setup procedures, lack real-time multi-source integration, and offer limited accessibility for direct data retrieval and analysis. We present VulGD, a dynamic open-access vulnerability graph database that continuously aggregates cybersecurity data from authoritative repositories. Designed for both expert and non-expert users, VulGD provides a unified web interface and a public API for interactive graph exploration and automated data access. Additionally, VulGD integrates embeddings from large language models (LLMs) to enrich vulnerability description representations, facilitating more accurate vulnerability risk assessment and threat prioritization. VulGD represents a practical and extensible platform for cybersecurity research and decision-making. The live system is publicly accessible at http://34.129.186.158/.
翻译:软件漏洞持续对现代信息系统构成重大威胁,需要及时准确的风险评估。国家漏洞数据库(NVD)和CVE详情等公共存储库虽定期更新,但主要采用缺乏对复杂互联结构原生支持的关系数据模型。为解决此问题,近期研究提出了基于图谱的漏洞模型。然而,这些系统通常需要复杂的安装配置、缺乏实时多源整合能力,且在数据直接检索与分析方面可访问性有限。我们提出VulGD——一种动态开放访问的漏洞图谱数据库,可持续聚合来自权威存储库的网络安全数据。VulGD专为专家及非专家用户设计,提供统一的Web界面与公共API,支持交互式图谱探索与自动化数据访问。此外,VulGD集成大语言模型(LLM)嵌入表示以丰富漏洞描述特征,促进更精确的漏洞风险评估与威胁优先级排序。VulGD为网络安全研究与决策提供了一个实用且可扩展的平台。系统实时版本可通过 http://34.129.186.158/ 公开访问。