KEV UPDATE 4 new vulnerabilities added to CISA Known Exploited list. Cisco SD-WAN, Chrome V8, Fortinet FortiOS. Patch deadlines active for federal agencies.
Free vulnerability intelligence

Patch what matters first.

NullCVE ranks every vulnerability by real-world risk. Know what to patch today, what can wait, and why. Built for your whole team, not just security specialists.

Data from
NVD CISA KEV EPSS GitHub Trickest
Vulnerability feed Live
All
Exploited
My stack
PoC live
CRIT
CVE-2025-21298
Windows OLE remote code execution — full SYSTEM access
KEVPoCEPSS 97%
98
NullScore
CRIT
CVE-2025-0282
Ivanti VPN unauthenticated remote code execution
KEVPoC
94
NullScore
HIGH
CVE-2025-21376
Windows LDAP race condition on domain controllers
KEVEPSS 76%
74
NullScore
MED
CVE-2025-25065
Microsoft Exchange SSRF, PoC publicly disclosed
PoCEPSS 42%
48
NullScore
0
Critical CVEs
0
KEV confirmed
0
PoC public
Free
No account needed
How it works

One score. Clear priority.

NullCVE pulls from seven data sources, fuses them into NullScore, and tells you exactly what to patch in plain English.

01
Data collected daily
We pull from NVD, CISA KEV, EPSS, GitHub Advisory, and Trickest every day and normalize everything into a single unified dataset.
02
NullScore ranks everything
Our composite model weighs CVSS severity, exploitation probability, active exploitation status, and public exploit availability into one number.
03
You see what matters
Filter to your tech stack. Go from 300 daily CVEs to the handful that actually affect your environment, ranked by urgency.
NullScore

Four signals that predict real risk

CVSS alone tells you severity. NullScore tells you urgency — the combination of how bad it is, how likely it is to be exploited, and whether it already is.

CVSS Severity35%
EPSS Probability25%
CISA KEV Status20%
PoC Availability15%
Stack Match Bonus+5%
Data sources

Seven sources. One feed.

We pull from the most trusted public vulnerability databases so you don't have to.

NVD / NIST
The authoritative CVE registry. CVSS scores and full vulnerability details on every record.
Live
CISA KEV
Confirmed actively exploited vulnerabilities. If it's on this list, attackers are using it right now.
Live
First.org EPSS
Exploitation probability score. The likelihood a CVE gets exploited in the next 30 days.
Live
GitHub Advisory
Open source package vulnerability database. Critical for development and DevOps teams.
Live
Trickest PoC
Tracks when working proof-of-concept exploit code becomes publicly available.
Live
OWASP
Maps CVEs to OWASP Top 10 categories for web application vulnerability context.
Live
Live feed

Vulnerabilities ranked by NullScore

Pricing

Start free. Upgrade when ready.

No credit card required. Free forever for individual use.

Free
$0 / forever
Everything you need to start prioritizing CVEs.
  • Live CVE feed, top 50 ranked daily
  • NullScore composite ranking
  • CISA KEV badge and status
  • Tech stack filter, 3 components
  • Plain English severity labels
Explore the feed
Most popular
Pro
$29 / month
For teams that need depth, alerts, and integrations.
  • Everything in Free
  • Unlimited CVE feed
  • Email and Slack alerts
  • Unlimited stack components
  • REST API access
  • Compliance mapping, PCI, SOC 2, HIPAA
  • AI plain English explanations
Enterprise
Custom
For organizations that need SSO, custom contracts, and compliance documentation.
  • Everything in Pro
  • SSO via SAML 2.0 / OIDC
  • Role-based access control
  • Custom compliance frameworks
  • 99.9% uptime SLA
  • On-premise deployment option
Contact sales

Start in 60 seconds.

No account required. No credit card. Open it and see what needs patching.

See live CVE feed Talk to us
NullScore
CVSS
EPSS
AI Explanation
Remediation Steps