Skip to content
English

How it works

How this site works

This site answers one question: among the security vulnerabilities in the products you use (firewalls, VPNs, Windows, browsers, email…), which ones are attackers actually exploiting, and which should you patch first?

Glossary

Vulnerability
A flaw in software or a device that an attacker can use, for example to take control of a computer or a firewall, or to read data.
CVE
The unique identifier of a vulnerability, in the form CVE-year-number (for example CVE-2020-0796). It lets everyone refer to the same vulnerability.
Exploited
Attacks using the vulnerability have actually been observed. Here, a vulnerability is called “exploited” only if it is listed in CISA’s KEV catalog.
KEV catalog (CISA)
“Known Exploited Vulnerabilities”: the official list, maintained by the US Cybersecurity and Infrastructure Security Agency (CISA), of vulnerabilities with confirmed exploitation, across all vendors. It is public and updated several times a week.
Brand
The manufacturer or publisher of the affected product (Fortinet, Cisco, Microsoft, Apple…), based on the name given by CISA.
Category
The type of product (firewalls and VPNs, operating systems, browsers, email…). Related categories are grouped together, for example “Network and edge”.
Edge device
A device that sits between your network and the internet (firewall, VPN, gateway, router): permanently exposed, it is a prime target.
Patch (security update)
The update released by the vendor to remove the vulnerability. Microsoft, for example, releases them every month on the second Tuesday (“Patch Tuesday”), and sometimes out of band.
End of life
A product its manufacturer no longer supports: no patch is coming. CISA then asks that it be removed or isolated from the network.
CISA deadline
The deadline CISA sets for US federal agencies to remediate a vulnerability. It only binds those agencies, but it is a useful measure of urgency.
Zero-day
A vulnerability exploited before, or on the same day as, the release of its patch: defenders had no head start.
CVSS severity
A score from 0 to 10 that measures how severe a vulnerability is (10 = most severe): 9 and above = critical, 7 to 8.9 = high, 4 to 6.9 = medium.
EPSS probability
An estimate, computed daily by a statistical model, of the likelihood that a vulnerability will be exploited in the next 30 days. Every vulnerability here is already exploited: EPSS is mostly useful to compare their activity.
Component, family (Microsoft)
The part of Windows or the Microsoft product affected (Exchange, Windows kernel, Active Directory…), grouped into families in the Microsoft section.
Ransomware
Malware that encrypts a victim’s data to demand a ransom. CISA flags the vulnerabilities known to be used in such attacks.
My radar
The list of products you follow, chosen on the Products page. The site then shows only the vulnerabilities that affect them.

The whole catalog, classified by product

The site covers CISA’s entire KEV catalog, whatever the vendor. Each vulnerability is filed under a brand and a product category.

  • An indicative classification: it is made by this site, from the vendor and product names given by CISA, using a hand-maintained catalog. It can be wrong about a product; each vulnerability page always shows the original name.
  • One main category per vulnerability, used for all counts. Some products are also linked to one or two neighboring categories, so that your radar finds them; they are never counted twice.
  • A brand not yet in the site’s catalog stays visible under its own name, in “Other products”, until it is classified: nothing is filed at random.
  • A high count is not a security rating: it also reflects how widely a product is deployed and how much attackers care about it.

Microsoft has its own section (Microsoft section): Microsoft publishes more detailed information (patch dates, affected products), which the site uses there.

How the “Patch first” list is ranked

  1. First, vulnerabilities added to the catalog in the last 30 days, newest to oldest: these are the most current attacks.
  2. Then those added within the year (between 31 days and one year old), from most to least severe (CVSS score). For equal scores, the most recently added comes first.
  3. Finally, all the others, older, from most to least severe, then newest to oldest.

In the last two groups, vulnerabilities without a published score come last. The CVSS score used is the NVD’s when there is one. Otherwise it is the one provided by the vendor or by CISA: the vulnerability page says which.

Two sections are kept separate from this list:

  • “End of life: remove”: vulnerabilities in products that are no longer supported. No patch is coming; the product must be removed or isolated. They are sorted from most to least recently added.
  • “To verify” (Microsoft only): vulnerabilities for which Microsoft states that no action is required on your part, because the fix was made in its online services (Entra ID…). Nothing to install, so they are not “to patch”, but they stay listed so you can verify it.

My radar

On the Products page, you can say what you use: a category (“Firewalls and VPNs”), a brand (“Fortinet”) or a brand within a category (“Microsoft › Email”). The “Patch first” list and the home page can then show only the vulnerabilities that affect those products.

  • This site knows nothing about your devices: your choices stay in this browser (local storage) and are never sent anywhere. No account, no cookies.
  • A display preference, not an assessment: the site computes no score or “risk” for you, it filters the facts in the catalog.
  • Cleared in one click (“Clear all” on the Products page). Another browser or device does not know about it. It is shared between the French and English versions of the site.

Where the data comes from, and when

Every day at around 6:30 UTC, the site automatically queries five public sources, checks the data, then updates itself. Every value shown states its source and when it was collected. If the update fails several days in a row, a banner says so at the top of every page. See the sources.

Content from the sources is shown in its original language: CISA and NVD texts are in English, CERT-FR advisories (the French government CERT) are in French.

Limits to keep in mind

  • Confirmed exploitation only: a vulnerability missing from the KEV catalog may be exploited without that being public yet. A brand or product with no vulnerability in the catalog is not flawless for all that.
  • Delays: several days can pass between an attack, its addition to the catalog and the site’s update.
  • US CISA deadlines: CISA’s deadlines bind US federal agencies. Elsewhere, they are a measure of urgency, not an obligation.
  • An indicative product classification: always check the exact product name and affected versions in the vendor’s security advisory.
  • Partial CERT-FR coverage: the site only follows CERT-FR’s latest publications. No advisory on a page does not mean none exists.
  • No personalized advice: the site knows nothing about your systems. Always check the vendor’s security advisory before acting.
  • Sometimes incomplete information: some older vulnerabilities have no score or patch date. The site says so instead of making it up.