About EVULNABLE
What this site is, who runs it, where its numbers come from, and what it is not.
What this is
EVULNABLE answers one question: of everything that is broken, what should you fix first?
Severity alone does not answer it. A CVSS 9.8 with no known exploitation signal may be less urgent than a 7.5 confirmed in active ransomware campaigns, and a list sorted by severity puts them the wrong way round. So this site combines confirmed exploitation, CISA's Known Exploited Vulnerabilities catalog, FIRST's EPSS probabilities, published CVSS and vendor advisories into one ranking, and shows its working on every entry.
Everything here is free, needs no account, and is usable by one person on one afternoon.
Who runs it
EVULNABLE is an independent project, operated from the United States. It is not affiliated with, sponsored by, or paid by any vendor it covers — not the scanner vendors compared on this site, not the penetration-testing firms, and not the vendors whose advisories it ranks. Nothing on this site is a paid placement, and there is no advertising.
That matters most on the two comparison pages, where a ranking is worth nothing if the ranker is being paid by one of the entries. Where a judgment is EVULNABLE's own rather than a vendor's published fact, those pages label it as such.
Reach a person at [email protected]. See Contact for reporting wrong data or requesting a correction.
How current the numbers are
Nothing here is typed in by hand. Every figure is fetched from the source that publishes it and cached for a bounded time, so a page is never older than its stated window:
| Source | What it provides | Refreshed |
|---|---|---|
| CISA KEV | Confirmed exploitation, ransomware association, federal remediation deadlines | Every 6 hours |
| Microsoft MSRC | The monthly Patch Tuesday release | Every 6 hours |
| FIRST EPSS | Exploitation probability and percentile | Every 12 hours |
| NIST NVD | CVE records and CVSS, on demand for search and enrichment | Every 12 hours |
| Vendor advisories | Cisco, Red Hat, Chrome, Ubuntu, Debian, Adobe, Oracle, Ivanti, Apple | Every 6 hours |
| CyberSecurityTracker.ai | Fixed versions and vendor required actions, used by scan analysis and search | On demand, plus a 24-hour refresh |
| Check Point Research | Per-CVE threat research coverage — title, date and link only, shown on CVE pages | Every 6 hours |
| endoflife.date | Microsoft end-of-life, end-of-support and ESU milestones | Every 24 hours |
| Vendor comparisons | Platform and pen-test vendor research | Dated on each page |
If a source is unreachable, the page says so and skips what it could not fetch. Nothing is estimated to fill a gap — an absent number is shown as absent, which is the difference between “checked, and it is not exploited” and “nobody has said”.
What this is not
- Not a replacement for your scanner. EVULNABLE has no idea what you run or how it is exposed. It ranks vulnerabilities, not your vulnerabilities — until you upload a scan, and then only for as long as that analysis is open.
- Not an authority on any CVE. Every record links back to the organization that published it. Where EVULNABLE and NVD disagree, NVD is the record and this is an opinion about urgency.
- Not a service with an SLA. There is no uptime guarantee and no support contract. It is free, and it is run accordingly.
- Not somewhere to put regulated data. See Privacy and data handling for exactly what happens to an upload, and decide from that rather than from this sentence.