Skip to content
English

Transparency

Sources and licenses

The site uses public data only, collected automatically every day. It produces no vulnerability information of its own: it gathers, classifies and dates what these five sources publish.

KEV catalog

CISA, the US Cybersecurity and Infrastructure Security Agency

The official list of vulnerabilities that attackers are known to exploit, with the date each was added and known use by ransomware. It is the only criterion used here to call a vulnerability “exploited”.

Last successful collection: September 29, 2026 at 14:57 UTC (version 2026.09.29).

Source website: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Exploitation data: CISA Known Exploited Vulnerabilities catalog, licensed under CC0 1.0. Its reuse does not imply any endorsement by CISA or DHS.

Security Update Guide

Microsoft Security Response Center (MSRC)

Microsoft’s own source, used for the Microsoft section and the pages of Microsoft vulnerabilities: affected product, patch date, whether action is required. Only facts are reused, never text written by Microsoft.

Last successful collection: September 29, 2026 at 14:57 UTC .

Source website: https://msrc.microsoft.com/update-guide

Microsoft vulnerability data: Microsoft Security Response Center, Security Update Guide. Reproduced for information only, without affiliation with or endorsement by Microsoft. Microsoft provides this information “as is”.

National Vulnerability Database (NVD)

NIST, the US National Institute of Standards and Technology

The CVSS severity score, the publication date and the official description of each vulnerability.

Last successful collection: September 29, 2026 at 15:00 UTC .

Source website: https://nvd.nist.gov/

CVE® descriptions: © The MITRE Corporation, reproduced under the CVE Program terms of use.

This product uses the NVD API but is not endorsed or certified by the NVD.

EPSS (Exploit Prediction Scoring System)

FIRST, the Forum of Incident Response and Security Teams

The probability, estimated daily by a statistical model, that a vulnerability will be exploited in the next 30 days.

Last successful collection: September 29, 2026 at 15:00 UTC .

Source website: https://www.first.org/epss/

EPSS scores: Exploit Prediction Scoring System (EPSS), FIRST, computed by Empirical Security.

CERT-FR

ANSSI, the French national cybersecurity agency

French security advisories and alerts that mention the vulnerability (in French).

Last successful collection: September 29, 2026 at 15:01 UTC .

Source website: https://www.cert.ssi.gouv.fr/

Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.

What the site does with the data

  • It reuses facts (identifiers, dates, brands and products, scores, indicators) and always links back to the original page.
  • It reuses neither text written by vendors nor any logo: brands are cited by name, to identify products.
  • Its only operations of its own are the ranking of the “Patch first” list, whose rule is public, and the indicative filing of each vulnerability by brand and product category, based on the names given by CISA: see the method.
  • Microsoft’s Security Update Guide (MSRC) is used for Microsoft products only: it feeds the Microsoft section and the pages of Microsoft vulnerabilities.
  • Brand pages link to the brand’s general security advisories page (its security home page, not the advisory for a specific vulnerability). These addresses are chosen and checked by hand, never copied from the sources.
  • Content from the sources is kept in its original language: CISA and NVD texts in English, CERT-FR titles in French.
  • The product and brand names cited (Microsoft, Windows, Fortinet, Cisco, Apple…) belong to their owners. The site is not affiliated with any of them.