Skip to content

Open data

Data library

Open datasets, fully documented — searchable here, and readable by any LLM.

  • NVD CVE disclosures + FIRST EPSS (agent-curated)

    New CVE disclosures with patch-priority intelligence (weekly)

    Weekly intelligence over newly disclosed CVEs: every CVE published by NIST NVD in the trailing 7 complete days (2026-09-18 → 2026-09-25 for this snapshot), joined with the FIRST EPSS daily 30-day exploitation-probability scores and scored for remediation triage. Each row carries the CVSS base score and severity (v3.1 preferred, then v3.0, then v2.0), exploitability metrics (attack vector / complexity / privileges required / user interaction), a remote-no-auth flag, the record's CWE ids mapped to one of 13 deterministic exploit categories, a 400-char plain-English summary, reference count, EPSS score + percentile + score date, and a documented 0-100 priority_score (45% CVSS + 35% EPSS percentile + 20% remote-exploitability bonus) ranked as disclosure_rank with p1–p4 priority tiers. Columns: ISO week, as-of date, CVE id / NVD URL / published / last-modified timestamps, summary, reference count, CVSS version/score/severity, the four exploitability metrics, remote-no-auth flag, CWE ids, exploit category, EPSS score/percentile/missing flag/score date, priority score/tier/rank, row hash. Primary key: (week, cve_id). Cadence: weekly. Nullability: cvss_* null when unrecorded; exploitability metrics null for v2-only records without a v3 vector; epss null with epss_missing=1 for CVEs absent from the EPSS feed. Caveats: ~2.5k CVEs/week — priority_score is a triage heuristic, not quantified risk; CWE coverage is incomplete; vendor/product columns were dropped (CPE configurations cover <2% of weekly disclosures). Agent-curated by intel-4 (2026-09-25): collection = keyless NVD API + EPSS CSV; transformation = dedupe + CVSS selection + CWE categorization + EPSS join + priority scoring. NVD content is public domain; EPSS is free of charge with no stated redistribution license — commercial_use = unclear. Sample use: order by disclosure_rank for this week's patch-priority list, or filter exploit_category = 'command-injection' and remote_no_auth = true for the internet-exposed RCE set.

    • technology
    • cybersecurity
    • signals
    • vulnerability
    rows
    2,520
    Quality
    90
    Updated
    Sep 25, 2026
    Fresh
    License
    License unclear

Use your own AI key

Once today's free allowance is used up, AI features can run on your own provider account.

Kept in this browser tab only (cleared when you close it) and sent with each AI request. Our servers use it for that request and never store or log it.