Observed arrival · 2026-09-23
CVE Triage: Three signals, one lookup
Paste a CVE ID to see its CVSS severity, EPSS exploitation estimate, and status in CISA’s Known Exploited Vulnerabilities catalog.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Security teams prioritizing vulnerability patches
- Worth noticing
- The FAQ distinguishes CVSS severity from exploitation likelihood and notes that EPSS is recomputed daily by FIRST.
Field notes
The FAQ explains that CVSS measures potential severity while EPSS estimates the likelihood of exploitation, and cautions that a high CVSS score alone does not establish active attacks. The page says FIRST recomputes EPSS daily and that the KEV catalog changes when CISA confirms newly exploited vulnerabilities. It identifies the project as a client-side prototype and says it is not affiliated with NVD, FIRST, or CISA.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
One card from the complete issue