NVD CVE disclosures + FIRST EPSS (agent-curated)
Weekly intelligence over newly disclosed CVEs: every CVE published by NIST NVD in the trailing 7 complete days (2026-09-18 → 2026-09-25 for this snapshot), joined with the FIRST EPSS daily 30-day exploitation-probability scores and scored for remediation triage. Each row carries the CVSS base score and severity (v3.1 preferred, then v3.0, then v2.0), exploitability metrics (attack vector / complexity / privileges required / user interaction), a remote-no-auth flag, the record's CWE ids mapped to one of 13 deterministic exploit categories, a 400-char plain-English summary, reference count, EPSS score + percentile + score date, and a documented 0-100 priority_score (45% CVSS + 35% EPSS percentile + 20% remote-exploitability bonus) ranked as disclosure_rank with p1–p4 priority tiers. Columns: ISO week, as-of date, CVE id / NVD URL / published / last-modified timestamps, summary, reference count, CVSS version/score/severity, the four exploitability metrics, remote-no-auth flag, CWE ids, exploit category, EPSS score/percentile/missing flag/score date, priority score/tier/rank, row hash. Primary key: (week, cve_id). Cadence: weekly. Nullability: cvss_* null when unrecorded; exploitability metrics null for v2-only records without a v3 vector; epss null with epss_missing=1 for CVEs absent from the EPSS feed. Caveats: ~2.5k CVEs/week — priority_score is a triage heuristic, not quantified risk; CWE coverage is incomplete; vendor/product columns were dropped (CPE configurations cover <2% of weekly disclosures). Agent-curated by intel-4 (2026-09-25): collection = keyless NVD API + EPSS CSV; transformation = dedupe + CVSS selection + CWE categorization + EPSS join + priority scoring. NVD content is public domain; EPSS is free of charge with no stated redistribution license — commercial_use = unclear. Sample use: order by disclosure_rank for this week's patch-priority list, or filter exploit_category = 'command-injection' and remote_no_auth = true for the internet-exposed RCE set.
- technology
- cybersecurity
- signals
- vulnerability