Observed arrival · 2026-09-18
CVE in Plain English
A public guide to security vulnerabilities that attackers have actually used, translated for people who do not speak security jargon.
- For
- People trying to understand urgent software vulnerabilities
- Worth noticing
- The catalog rebuilds automatically at 06:17 UTC and keeps vulnerabilities after affected software is obsolete.
Field notes
The project uses two public vulnerability sources rather than hand-maintained entries, and says its catalog is rebuilt automatically at a fixed daily time. Its stated update rate is three or four days per week, averaging about 25 additions per month. Entries remain in the catalog after the affected software is no longer in use, preserving historical context. The site explicitly limits its role: it explains public records but does not inspect a visitor’s devices or infer their software inventory.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue