Knowledge base
CVE prioritisation guides
Practical, vendor-neutral explainers on the signals that decide which vulnerabilities actually matter — and how to act on them.
All guides
-
CVSS vs EPSS: severity is not the same as risk
CVSS tells you how bad a flaw could be. EPSS tells you how likely it is to be exploited. Using them together is the whole point.
Read guide -
The CISA KEV catalog: the vulnerabilities already being exploited
KEV is CISA’s list of CVEs confirmed to be exploited in the wild. If a CVE is on it, the debate about whether to patch is over.
Read guide -
How to prioritise vulnerabilities: a practical playbook
You can’t patch everything. Here’s a repeatable way to decide what to fix first, using exploitation, exposure and severity.
Read guide