
- CVEs tracked
- CVEs tracked
- Vendors tracked
- Vendors tracked
- CVEs in CISA KEV
- CVEs in CISA KEV
- CNA data sources
- CNA data sources
CVE data from the organizations that publish it
We collect CVE records from CVE Numbering Authorities, including these.
See every change to a CVE as it happens.
A dated timeline shows when a public exploit appears, when CISA adds the CVE to KEV, and when the SSVC decision changes to exploited.
- Public exploit & PoC activity
- CISA KEV additions
- SSVC decision changes
- Every field-level change, dated

See every CVE that affects your stack in one list.
Filter all CVEs by vendor, product, severity, EPSS, and CISA KEV status, and save each filter set as a view.

See the exploits, detections, and affected products for each CVE.
Each CVE lists its public exploits, detection rules, and affected vendors and products on one screen.
- Exploits: Metasploit, ExploitDB, Nuclei & GitHub PoCs
- Detections: Sigma, YARA, Snort, Suricata, Splunk & Sentinel
- Every affected vendor and product, deduplicated
- CISA KEV status & EPSS percentile
- AI explanations and mitigations
- PDF export

Free security tools and data
Search CWEs, CAPEC patterns, vendors, and CNAs, and score CVSS vectors without an account.
CWE Weakness Directory
Each CWE weakness explained in plain English, with its CVE and KEV counts.
CAPEC Attack Patterns
Attack patterns mapped to the CWEs and CVEs they target.
Vulnerabilities by Vendor
CVE counts, CISA KEV totals, and severity breakdowns for each vendor.
CNA Data-Quality Leaderboard
How completely each CVE Numbering Authority fills in its CVE records.
CVSS Calculator
Score CVSS 2.0 to 4.0 vectors, with a metric breakdown that matches FIRST.org.
Security Glossary
CVE, CVSS, EPSS, CISA KEV, CWE, and CAPEC explained in plain English.
Send CVE data to the tools you already run.
Query every CVE through the read-only REST API, get email alerts for the CVEs you track, and export detection and remediation content.
- Read-only REST API (v1)
- Email alerts for tracked CVEs
- Sigma, YARA, Snort, Splunk & Sentinel rules
- Ansible, Bash & PowerShell remediation
