Our story

Built by people tired of the noise.

NullCVE started as a frustration. Too many CVEs, too little context, and tools built for specialists — not the people actually responsible for keeping systems safe.

Why we built this

The problem with existing tools

Working in enterprise software deployment means dealing with patch management every day. The question that never had a clear answer: which CVE do we patch first?

NVD gives you raw data. CVEDetails gives you more data. CISA publishes a KEV list. First.org publishes EPSS scores. Trickest tracks public exploits. All of it lives in different places, in different formats, built for different audiences.

The IT manager, the help desk lead, the release coordinator — the people actually responsible for getting patches deployed — were expected to figure it out themselves. That gap causes real incidents.

So we built NullCVE. One feed. One score. Plain English. No security degree required.

Our mission
Make vulnerability intelligence accessible to everyone responsible for keeping systems safe.
Not just security engineers. The IT manager, the help desk team, the release coordinator — everyone who deals with patches deserves a clear answer to which one matters most.
What we stand for

Our values

Three principles that guide every decision we make about the platform.

Clarity over complexity
Every feature we build has to make vulnerability data easier to understand, not harder. If it requires a security background to interpret, we haven't done our job.
Data integrity first
We source from the most trusted public databases and are transparent about our methodology. NullScore is documented and open. No black boxes.
Built for practitioners
The people who actually patch systems aren't always security specialists. We build for the full team, not just the most technical person in the room.
Data sources

Where the data comes from

NullCVE pulls from seven trusted public sources, refreshed daily.

NVD / NIST
Authoritative CVE registry with CVSS scores and full vulnerability details.
Live
CISA KEV
Confirmed actively exploited vulnerabilities. The most important signal for urgency.
Live
First.org EPSS
Exploitation probability scores. The likelihood of exploitation in the next 30 days.
Live
GitHub Advisory
Open source package vulnerability database. Critical for dev and DevOps teams.
Live
Trickest PoC
Tracks when working proof-of-concept exploit code becomes publicly available.
Live
OWASP
Maps CVEs to OWASP Top 10 categories for web application context.
Live
Who built this

The team

Tomas Hernandez
Founder, Deployment and Release Manager
Over 10 years in enterprise SaaS delivery. Built NullCVE after years of dealing with CVE triage as part of release management at a mortgage technology platform serving hundreds of financial institutions. Tired of not having a clear answer to which vulnerability to patch first.

Ready to get started?

Free forever. No account required. Know what to patch in 60 seconds.

See live CVE feed Talk to us