NullCVE started as a frustration. Too many CVEs, too little context, and tools built for specialists — not the people actually responsible for keeping systems safe.
Working in enterprise software deployment means dealing with patch management every day. The question that never had a clear answer: which CVE do we patch first?
NVD gives you raw data. CVEDetails gives you more data. CISA publishes a KEV list. First.org publishes EPSS scores. Trickest tracks public exploits. All of it lives in different places, in different formats, built for different audiences.
The IT manager, the help desk lead, the release coordinator — the people actually responsible for getting patches deployed — were expected to figure it out themselves. That gap causes real incidents.
So we built NullCVE. One feed. One score. Plain English. No security degree required.
Three principles that guide every decision we make about the platform.
NullCVE pulls from seven trusted public sources, refreshed daily.
Free forever. No account required. Know what to patch in 60 seconds.