HOW IT WORKS
Every vulnerability scanner you own rates almost everything critical. This one asks a different question: not how bad could it be, but “is anyone actually exploiting it?”
SEVERITY IS NOT URGENCY
These two are in the database right now. Sorted by CVSS, the first one wins. Sorted by what is being exploited today, it is not close.
CVE-2026-19478
GitLab has remediated an issue in GitLab CE/EE affecting all versions
- CVSS
- 9.4
- EPSS
- 6.0%
- RANSOMWARE
- no
Severe on paper. Nobody is using it.
CVE-2019-7481
SonicWall SMA100
- CVSS
- 7.5
- EPSS
- 99.9%
- RANSOMWARE
- YES
Mid-range severity. Everybody is using it.
THREE SIGNALS, IN ORDER OF HONESTY
The score is 0–100, built from three public sources. They are weighted by how much each one actually tells you about your Tuesday.
CISA KEV
Is it already happening?+40, plus 10 more for ransomwareCISA's Known Exploited Vulnerabilities catalogue lists what has been observed being exploited in the wild. Not theorised, not proof-of-concept — used. It is the single strongest thing anyone can say about a vulnerability, so it outweighs everything else here combined.
EPSS
How likely is it to start?up to +25FIRST.org's Exploit Prediction Scoring System gives the probability a vulnerability will be exploited in the next 30 days, trained on what actually got exploited historically. It is the best available answer to “should I worry about this one yet”.
CVSS
How bad would it be?up to +15, plus 10 for reachabilityThe severity score every scanner already shows you. It matters — but it describes a worst case, not a likelihood, which is why it counts for less here than the two signals about reality. Network-reachable, no-auth, no-interaction adds a little more.
WHAT THE NUMBER MEANS
- 0–19STEADYIt's Tuesday.
- 20–39ELEVATEDBacklog it.
- 40–59RACINGThis one's on the roadmap now.
- 60–79SPIKINGCancel your afternoon.
- 80–94CRITICALCancel your weekend.
- 95–100CODE REDWake people up.
Everything in CISA KEV starts at 48, because confirmed exploitation alone is worth most of the range. The lower two bands are reserved for vulnerabilities nobody has been caught using yet.
AND THEN A HUMAN OVERRULES IT
The maths is a starting point, not a verdict. Anything published here has been read by a person who can drag the marker wherever they think it belongs — and when they do, the meter shows a HAND‑TUNED mark rather than hiding it. A pre-auth flaw in something that fronts your whole estate can deserve 80 on the day it drops, weeks before it reaches any catalogue.
That is the difference between this and a feed. The machine watches 1695 vulnerabilities so nobody has to. The short list is short because somebody decided it should be.
WHAT THIS IS NOT
- Not a scanner. It has no idea what you run. It tells you what is being exploited; matching that to your estate is still your job.
- Not complete. The corpus is CISA KEV, not the whole CVE list. Something absent here is not safe — it is unproven.
- Not a replacement for your process. It is a second opinion on priority, aimed at the moment you have twenty criticals and time for three.