What We Build

Everything in
the NullCVE platform.

From a free live feed to enterprise compliance reports, here's the full picture of what NullCVE offers and what's coming next.

nullcve.io/feed
CRITICAL CVE-2025-21298 Windows OLE RCE , SYSTEM control 98
CRITICAL CVE-2025-0282 Ivanti VPN , unauthenticated RCE 94
CRITICAL CVE-2024-55591 FortiOS , admin bypass via WebSocket 91
HIGH CVE-2025-21376 Windows LDAP , domain controller RCE 74
MEDIUM CVE-2025-25065 Exchange SSRF , bounty PoC disclosed 48
Free

NullScore™ CVE Dashboard

The core product. A ranked, filterable feed of every CVE that matters, fused from 7 sources into one list, ordered by real-world risk. No security degree required to understand it.

  • NullScore™ composite ranking (CVSS + EPSS + KEV + PoC)
  • Plain English severity labels : "Patch in 24 hours" not "CVSS 9.8"
  • CISA KEV badges : actively exploited vulnerabilities flagged instantly
  • Tech stack filter : see only CVEs affecting your environment
  • Role-based views for Analyst, Developer, and IT/Compliance
  • Built-in glossary : every term explained on first use
Open live feed → See pricing
GET /api/v1/vulnerabilities
// NullCVE REST API: Pro plan

"data": [
  {
    "cve_id": "CVE-2025-21298",
    "null_score": 98,
    "severity": "CRITICAL",
    "cvss": 9.8,
    "epss": 0.97,
    "is_kev": true,
    "poc_available": true,
    "action": "Patch in 24 hours"
  }
]
Pro

REST API

Integrate NullCVE data directly into your security tooling, SIEM, ticketing system, or internal dashboards. Clean JSON, consistent schema, NullScore on every record.

  • Full NullScore™ + EPSS data on every CVE record
  • Filter by severity, KEV status, PoC, EPSS threshold, stack
  • Daily JSON and CSV bulk export
  • Webhook support for new KEV additions and score changes
  • Versioned API with deprecation notices
  • Rate limits matched to your plan tier
Get Pro access → API docs
PCI-DSS 4.0 Compliance Map
Req 6.3 Vulnerabilities identified and addressed 8 CVEs
Req 6.4 Public-facing apps protected 3 CVEs
Req 11.3 Pen test requirements 2 CVEs
!
Req 8.3 Strong authentication enforced 0 CVEs
Req 10.2 Audit log mechanisms 0 CVEs
Pro

Compliance Mapping

Automatically map your CVEs to the compliance frameworks your auditors actually care about. Generate evidence packs without touching a spreadsheet.

  • PCI-DSS 4.0 : Requirements 6.x, 8.x, 10.x, 11.x, 12.x
  • SOC 2 Type II : Trust Service Criteria mapping
  • HIPAA : Technical Safeguards section
  • NIST CSF 2.0 : Including the new Govern function
  • One-click audit export PDF
  • Remediation status tracking per control
Unlock compliance → Request a demo
Smart Alerts
🔴
CVE-2025-21298: Critical · In Your Stack
Windows OLE RCE · NullScore 98 · KEV confirmed · PoC published
2 minutes ago · via Slack
🟠
CVE-2024-55591 added to CISA KEV
FortiOS Auth Bypass · NullScore 91 · Actively exploited
1 hour ago · via email
🔕 3 Medium CVEs suppressed, below your threshold of NullScore 70
Pro

Smart Alerts

Get notified the moment something critical drops that actually affects your environment. No noise, no manual checking, just the signal that requires action.

  • Email, Slack, and Microsoft Teams delivery
  • Configurable NullScore threshold : only alert when it matters
  • Stack-filtered : never alerted about software you don't run
  • Instant KEV alerts : notified within 1hr of CISA additions
  • PoC publish alerts : know when exploit code goes public
  • Weekly digest : top 10 CVEs every Monday morning
Set up alerts →
SSO
SAML 2.0 / OIDC
Okta, Azure AD, Google
RBAC
Team Roles
Analyst · Dev · CISO · Admin
SLA
99.9% Uptime
Contractual guarantee
DPA
Data Processing
GDPR · CCPA compliant
Enterprise

Enterprise Plan

For organizations that need team management, custom contracts, and the compliance documentation to get NullCVE through procurement. Everything in Pro, plus the enterprise layer.

  • SSO via SAML 2.0 / OIDC (Okta, Azure AD, Google)
  • Role-based access for your whole team
  • Custom compliance frameworks
  • Guaranteed SLA with uptime commitment
  • Data Processing Agreement for GDPR/CCPA
  • Dedicated support Slack channel
  • On-premise deployment option
Contact sales →
How We Compare

NullCVE vs. the alternatives.

Feature NullCVE CVEDetails NVD / NIST Recorded Future
Composite risk score
CISA KEV integration
EPSS scoring
Live PoC tracking Pro Partial
Tech stack filtering Partial
Plain English for non-security users
Compliance mapping (PCI, SOC2, HIPAA) Pro Enterprise
Free tier
Starting price $0 / $29 Pro $0 / ~$99 Business Free $25,000+/yr

Ready to get started?

Free forever. No credit card. Set up in under 2 minutes.