About EVULNABLE

What this site is, who runs it, where its numbers come from, and what it is not.

What this is

EVULNABLE answers one question: of everything that is broken, what should you fix first?

Severity alone does not answer it. A CVSS 9.8 with no known exploitation signal may be less urgent than a 7.5 confirmed in active ransomware campaigns, and a list sorted by severity puts them the wrong way round. So this site combines confirmed exploitation, CISA's Known Exploited Vulnerabilities catalog, FIRST's EPSS probabilities, published CVSS and vendor advisories into one ranking, and shows its working on every entry.

Everything here is free, needs no account, and is usable by one person on one afternoon.

Who runs it

EVULNABLE is an independent project, operated from the United States. It is not affiliated with, sponsored by, or paid by any vendor it covers — not the scanner vendors compared on this site, not the penetration-testing firms, and not the vendors whose advisories it ranks. Nothing on this site is a paid placement, and there is no advertising.

That matters most on the two comparison pages, where a ranking is worth nothing if the ranker is being paid by one of the entries. Where a judgment is EVULNABLE's own rather than a vendor's published fact, those pages label it as such.

Reach a person at [email protected]. See Contact for reporting wrong data or requesting a correction.

How current the numbers are

Nothing here is typed in by hand. Every figure is fetched from the source that publishes it and cached for a bounded time, so a page is never older than its stated window:

Data sources and how often each is refreshed
SourceWhat it providesRefreshed
CISA KEVConfirmed exploitation, ransomware association, federal remediation deadlinesEvery 6 hours
Microsoft MSRCThe monthly Patch Tuesday releaseEvery 6 hours
FIRST EPSSExploitation probability and percentileEvery 12 hours
NIST NVDCVE records and CVSS, on demand for search and enrichmentEvery 12 hours
Vendor advisoriesCisco, Red Hat, Chrome, Ubuntu, Debian, Adobe, Oracle, Ivanti, AppleEvery 6 hours
CyberSecurityTracker.aiFixed versions and vendor required actions, used by scan analysis and searchOn demand, plus a 24-hour refresh
Check Point ResearchPer-CVE threat research coverage — title, date and link only, shown on CVE pagesEvery 6 hours
endoflife.dateMicrosoft end-of-life, end-of-support and ESU milestonesEvery 24 hours
Vendor comparisonsPlatform and pen-test vendor researchDated on each page

If a source is unreachable, the page says so and skips what it could not fetch. Nothing is estimated to fill a gap — an absent number is shown as absent, which is the difference between “checked, and it is not exploited” and “nobody has said”.

What this is not

  • Not a replacement for your scanner. EVULNABLE has no idea what you run or how it is exposed. It ranks vulnerabilities, not your vulnerabilities — until you upload a scan, and then only for as long as that analysis is open.
  • Not an authority on any CVE. Every record links back to the organization that published it. Where EVULNABLE and NVD disagree, NVD is the record and this is an opinion about urgency.
  • Not a service with an SLA. There is no uptime guarantee and no support contract. It is free, and it is run accordingly.
  • Not somewhere to put regulated data. See Privacy and data handling for exactly what happens to an upload, and decide from that rather than from this sentence.

How the score works

The EVULNABLE Risk Score, what it weighs, and why an entry can rank above a higher CVSS are all set out on the Methodology page, including the cases where the score deliberately abstains rather than guesses.